Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: browser.newtab.url ändert sich selbstständig auf "search.conduit.com"

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 19.02.2014, 15:16   #1
Robin0308
 
browser.newtab.url ändert sich selbstständig auf "search.conduit.com" - Standard

browser.newtab.url ändert sich selbstständig auf "search.conduit.com"



Guten Tag zusammen,

ich habe seit nun schon ca. 1 Woche das Problem, das sich die browser.newtab.url immer wieder von "google.de" auf "search.conduit.com" ändert. Das ist nicht nur nervig sondern, wie ich bereits gelesen habe, ein Virus o.ä..
Nun wollte ich einmal fragen, was man den dagegen machen kann.
Mein Antiviren Programm hat übrigens nichts ausgespuckt. (Avast! Free)

Vielen Dank schonmal,
Robin

Alt 19.02.2014, 15:50   #2
schrauber
/// the machine
/// TB-Ausbilder
 

browser.newtab.url ändert sich selbstständig auf "search.conduit.com" - Standard

browser.newtab.url ändert sich selbstständig auf "search.conduit.com"



hi,

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

__________________

__________________

Alt 19.02.2014, 17:46   #3
Robin0308
 
browser.newtab.url ändert sich selbstständig auf "search.conduit.com" - Standard

browser.newtab.url ändert sich selbstständig auf "search.conduit.com"



FRST:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-02-2014
Ran by Robin (administrator) on ROBIN-PC on 19-02-2014 17:41:56
Running from C:\Users\Robin\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(AVAST Software) D:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(ICQ) C:\Users\Robin\AppData\Roaming\ICQM\icq.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Valve Corporation) D:\Program Files (x86)\Steam\Steam.exe
() C:\Program Files (x86)\Zapp\WConnectorProductivity.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIHAE.EXE
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Skype Technologies S.A.) D:\Program Files (x86)\Skype\Phone\Skype.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIHAE.EXE
(Smartbar) C:\Users\Robin\AppData\Local\Smartbar\Application\Shopop.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() D:\Program Files\Hear\Hear.exe
(TeamViewer GmbH) D:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Apple Inc.) D:\Program Files (x86)\iTunes\iTunesHelper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(AVAST Software) D:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Conduit) C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe
(Conduit) C:\Program Files (x86)\SearchProtect\SearchProtect\bin\cltmng.exe
(Conduit) C:\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(LogMeIn Inc.) D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(LogMeIn Inc.) D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(LogMeIn, Inc.) D:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(LogMeIn, Inc.) D:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncV1\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(File Type Advisor) C:\Program Files (x86)\File Type Advisor\fileadvisor.exe
(SEIKO EPSON CORPORATION) C:\Windows\system32\spool\DRIVERS\x64\3\E_IARNHAE.EXE
() D:\Program Files (x86)\Steam\steamapps\common\rust\rust.exe
(Valve Corporation) D:\Program Files (x86)\Steam\GameOverlayUI.exe
(Mozilla Corporation) D:\Program Files\Waterfox\waterfox.exe
(Mozilla Corporation) D:\Program Files\Waterfox\plugin-container.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Nvtmru] - "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap64.dll [1179576 2014-01-21] (NVIDIA Corporation)
HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-01-21] (NVIDIA Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-12-10] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BCSSync] - D:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - D:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] - D:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2239376 2014-02-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] - D:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-02-03] (AVAST Software)
HKLM-x32\...\Run: [mobilegeni daemon] - C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3813712 2014-02-04] (LogMeIn Inc.)
HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\Windows\System32\SPReview\SPReview.exe [301568 2013-08-12] (Microsoft Corporation)
HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [DAEMON Tools Lite] - D:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [icq] - C:\Users\Robin\AppData\Roaming\ICQM\icq.exe [28698984 2013-08-06] (ICQ)
HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [Steam] - D:\Program Files (x86)\Steam\steam.exe [1824000 2014-02-11] (Valve Corporation)
HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [Google Update*] - [X] <===== ATTENTION (ZeroAccess rootkit hidden path)
HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [Skype] - D:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [Facebook Update] - C:\Users\Robin\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-01-19] (Facebook Inc.)
HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [EPLTarget\P0000000000000001] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [Browser Infrastructure Helper] - C:\Users\Robin\AppData\Local\Smartbar\Application\Shopop.exe [21040 2013-12-31] (Smartbar)
HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [NextLive] - C:\Windows\SysWOW64\rundll32.exe "C:\Users\Robin\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\MountPoints2: {41b2eb50-fde3-11e2-8e7d-bc5ff48acc01} - H:\cdstart.exe
HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\MountPoints2: {52ebdb9a-fd50-11e2-8ecc-806e6f6e6963} - F:\start.exe
HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\MountPoints2: {93b25906-fd4d-11e2-af92-806e6f6e6963} - F:\SETUP.EXE
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll [1351456 2014-02-06] (Conduit)
AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll => C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll [1047328 2014-02-06] (Conduit)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.certified-toolbar.com?si=66807&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&st=chrome&q=
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP32A90F07-5575-4C79-96E3-CFDB19C3D552&SSPV=
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA1AB3F2ADF98CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.certified-toolbar.com?si=66807&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&st=chrome&q=
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.certified-toolbar.com?si=66807&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&st=chrome&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://search.certified-toolbar.com?si=66807&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&st=chrome&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://search.certified-toolbar.com?si=66807&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&st=chrome&q=
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.certified-toolbar.com?si=66807&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&st=chrome&q=
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {D9EE0C5C-6202-4940-AAAA-A7765605E923} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKLM - {D9EE0C5C-6202-4940-AAAA-A7765605E923} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKLM-x32 - DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.certified-toolbar.com?si=66807&st=bs&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&q={searchTerms}
SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.certified-toolbar.com?si=66807&st=bs&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&q={searchTerms}
SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP32A90F07-5575-4C79-96E3-CFDB19C3D552&q={searchTerms}&SSPV=
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP32A90F07-5575-4C79-96E3-CFDB19C3D552&q={searchTerms}&SSPV=
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.certified-toolbar.com?si=66807&st=bs&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&q={searchTerms}
SearchScopes: HKCU - {D9EE0C5C-6202-4940-AAAA-A7765605E923} URL = hxxp://www.sm.de/?q={searchTerms}
BHO: Zapp - {14264a21-01fa-455f-a9c4-7c8b3d82b6f6} - C:\Program Files\Zapp\IE\Zapp.dll (Simply Tech LTD.)
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - D:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Shopop WidgetEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\system32\mscoree.dll (Microsoft Corporation)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Java\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Java\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Zapp - {14264a21-01fa-455f-a9c4-7c8b3d82b6f6} - C:\Program Files (x86)\Zapp\IE\Zapp.dll (Simply Tech LTD.)
BHO-x32: Shopop WidgetEngine - {31ad400d-1b06-4e33-a59a-90c2c140cba0} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - D:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - D:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM - Zapp - {14264a21-01fa-455f-a9c4-7c8b3d82b6f6} - C:\Program Files\Zapp\IE\Zapp.dll (Simply Tech LTD.)
Toolbar: HKLM - Shopop Widget - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\system32\mscoree.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM-x32 - Zapp - {14264a21-01fa-455f-a9c4-7c8b3d82b6f6} - C:\Program Files (x86)\Zapp\IE\Zapp.dll (Simply Tech LTD.)
Toolbar: HKLM-x32 - Shopop Widget - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\SysWOW64\mscoree.dll (Microsoft Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 07 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5-x64 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 07 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870
FF NewTab: hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=69&CUI=&SSPV=&Lay=1&UM=4&UP=SP32A90F07-5575-4C79-96E3-CFDB19C3D552
FF SelectedSearchEngine: Google
FF Homepage: hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP32A90F07-5575-4C79-96E3-CFDB19C3D552&SSPV=
FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*')%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1))%20%7B%20return%20'PROXY%20nq-us07.personalitycores.com%3A8000%3B%20PROXY%20nq-us06.personalitycores.com%3A8000%3B%20PROXY%20nq-us11.personalitycores.com%3A8000%3B%20PROXY%20nq-us09.personalitycores.com%3A8000%3B%20PROXY%20nq-us05.personalitycores.com%3A8000%3B%20PROXY%20nq-us04.personalitycores.com%3A8000%3B%20PROXY%20nq-us08.personalitycores.com%3A8000%3B%20PROXY%20nq-us10.personalitycores.com%3A8000%3B%20PROXY%20nq-us12.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"
FF NetworkProxy: "type", 2
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - D:\Java\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - D:\Java\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.3 - D:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - D:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - D:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Robin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Robin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\searchplugins\search_engine.xml
FF Extension: Zapp - C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\Extensions\{70ba6a57-dc09-4a3e-bbe1-dfb10af77244} [2014-02-15]
FF Extension: No Name - C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2013-12-19]
FF Extension: No Name - C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\Extensions\langpack-de@firefox.mozilla.org.xpi [2014-02-05]
FF Extension: No Name - C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-19]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - D:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - D:\Program Files\AVAST Software\Avast\WebRep\FF [2013-08-27]
FF StartMenuInternet: FIREFOX.EXE - D:\Program Files\Mozilla Firefox\firefox.exe

==================== Services (Whitelisted) =================

R2 avast! Antivirus; D:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-02-03] (AVAST Software)
R2 CltMngSvc; C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [2360608 2014-02-06] (Conduit)
R2 Hamachi2Svc; D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2222416 2014-02-04] (LogMeIn Inc.)
S3 Microsoft SharePoint Workspace Audit Service; D:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [30969208 2010-03-25] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-01-21] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16939296 2014-01-21] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-09] ()
S2 SkypeUpdate; D:\Program Files (x86)\Skype\Updater\Updater.exe [172192 2013-10-23] (Skype Technologies)
R2 TeamViewer8; D:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [4308320 2013-08-07] (TeamViewer GmbH)
S2 WinkHandler; C:\Program Files (x86)\Iminent\WinkHandler.exe [X]
S2 *etadpug; "C:\Program Files (x86)\Google\Desktop\Install\{6294d68b-ece8-cdc3-21a7-ee57dc57ec05}\   \...\???\{6294d68b-ece8-cdc3-21a7-ee57dc57ec05}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess)

==================== Drivers (Whitelisted) ====================

R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-02-03] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-11-23] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-23] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-02-03] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-02-03] (AVAST Software)
R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-02-03] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2014-01-16] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-08-05] (DT Soft Ltd)
S3 GPCIDrv; C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [14376 2010-02-04] ()
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-27] (NVIDIA Corporation)
R3 REN2CAP_DRIVER; C:\Windows\System32\drivers\ren2cap.sys [46728 2011-11-07] ()
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-02-19 17:41 - 2014-02-19 17:42 - 00026078 _____ () C:\Users\Robin\Desktop\FRST.txt
2014-02-19 17:41 - 2014-02-19 17:41 - 02153472 _____ (Farbar) C:\Users\Robin\Desktop\FRST64.exe
2014-02-19 17:41 - 2014-02-19 17:41 - 00000000 ____D () C:\FRST
2014-02-18 22:40 - 2014-02-18 22:40 - 00000000 ____D () C:\Users\Robin\AppData\Local\My Games
2014-02-18 22:28 - 2014-02-18 22:28 - 00000221 _____ () C:\Users\Robin\Desktop\Sid Meier's Civilization V - Demo.url
2014-02-18 21:23 - 2014-02-18 21:23 - 00006477 _____ () C:\Users\Robin\AppData\Local\recently-used.xbel
2014-02-16 17:01 - 2014-02-16 17:01 - 00000000 ____D () C:\Users\Robin\.MCTranscodingSDK
2014-02-16 17:00 - 2014-02-16 17:05 - 00000000 ____D () C:\Users\Public\Documents\Lightworks
2014-02-16 17:00 - 2014-02-16 17:00 - 00000000 ____D () C:\ProgramData\Geevs
2014-02-15 22:44 - 2014-02-15 22:46 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Systweak
2014-02-15 22:44 - 2014-02-15 22:44 - 00000000 ____D () C:\Users\Robin\AppData\Local\Smartbar
2014-02-15 22:44 - 2013-08-22 18:36 - 00020312 _____ (Systweak Inc., (www.systweak.com)) C:\Windows\system32\roboot64.exe
2014-02-15 22:19 - 2014-02-15 22:29 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Windows\System32\Tasks\SystemSockets
2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Windows\System32\Tasks\Browser Updater
2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\SimplyTech
2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Program Files\Zapp
2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Program Files (x86)\Zapp
2014-02-15 21:59 - 2014-02-04 06:36 - 00033864 _____ () C:\Windows\Launcher.exe
2014-02-15 21:18 - 2014-02-15 21:18 - 00015130 _____ () C:\Users\Robin\Documents\Mein Film.wlmp
2014-02-15 20:34 - 2014-02-15 20:52 - 591803806 _____ () C:\Users\Robin\Desktop\template.avi
2014-02-15 20:34 - 2014-02-15 20:52 - 591803806 _____ () C:\Users\Robin\Desktop\A_template.avi
2014-02-15 19:16 - 2014-02-16 22:37 - 00000000 ____D () C:\Users\Robin\Desktop\INTRO TEMPLATE BY RenttuArts
2014-02-13 15:28 - 2014-02-13 15:28 - 00000000 ____D () C:\Windows\SysWOW64\SearchProtect
2014-02-12 22:45 - 2014-02-12 22:45 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-02-12 22:45 - 2014-02-12 22:45 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-02-12 22:45 - 2014-02-12 22:45 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-02-12 22:45 - 2014-02-12 22:45 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-02-10 19:33 - 2014-02-10 19:33 - 00000934 _____ () C:\Users\Robin\Desktop\Landwirtschafts Simulator 2013 .lnk
2014-02-10 17:26 - 2014-02-10 17:26 - 00000000 ____D () C:\Users\Robin\AppData\Local\EdgeOfReality
2014-02-10 16:08 - 2014-02-10 16:08 - 00000222 _____ () C:\Users\Robin\Desktop\Loadout.url
2014-02-09 22:33 - 2014-02-14 23:32 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\vlc
2014-02-09 22:33 - 2014-02-09 22:33 - 00001184 _____ () C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk
2014-02-09 22:33 - 2014-02-09 22:33 - 00000757 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-02-09 17:25 - 2014-02-09 17:25 - 00000836 _____ () C:\Users\Public\Desktop\Prime Time.lnk
2014-02-05 18:57 - 2014-02-17 22:31 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\.minecraft
2014-02-04 16:51 - 2014-02-04 16:51 - 00003012 _____ () C:\Windows\System32\Tasks\{29949044-F7D7-4E68-B9CE-644E4CFDA5BB}
2014-02-03 20:36 - 2014-02-03 20:36 - 00001648 _____ () C:\Users\Robin\Desktop\Euro Truck Simulator 2.lnk
2014-02-03 18:45 - 2014-02-03 18:45 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1-click run
2014-02-03 18:44 - 2014-02-03 18:44 - 00000000 ____D () C:\2-click run
2014-02-03 18:40 - 2014-02-13 15:29 - 00000000 ____D () C:\Program Files (x86)\SearchProtect
2014-02-03 18:40 - 2014-02-03 18:40 - 00000000 ____D () C:\Users\Robin\AppData\Local\SearchProtect
2014-01-30 16:10 - 2014-01-30 16:10 - 00012834 _____ () C:\Users\Robin\Desktop\Anno2070.lnk
2014-01-30 16:02 - 2014-01-30 16:02 - 00001468 _____ () C:\Users\Robin\Desktop\Flight Simulator X.lnk
2014-01-29 20:02 - 2014-01-29 20:02 - 00038960 _____ () C:\Windows\SysWOW64\RGBAcodec.dll
2014-01-28 21:01 - 2014-02-16 17:46 - 00000000 ___RD () C:\Users\Robin\Desktop\Aufnehmzeug
2014-01-26 21:29 - 2013-12-19 21:33 - 30372640 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 22960416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 18222008 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 12645664 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-01-26 21:29 - 2013-12-19 21:33 - 11605752 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 11554264 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 09700224 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 09657464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 03132704 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 03125024 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 02947872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 02747680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433221.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433221.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 01242400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00882464 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00879392 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00852768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00847648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00479520 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00405280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00357152 _____ () C:\Windows\system32\NvIFROpenGL.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00314656 _____ () C:\Windows\SysWOW64\NvIFROpenGL.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2014-01-26 21:29 - 2013-11-28 14:38 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2014-01-26 21:29 - 2013-11-28 14:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2014-01-26 21:29 - 2013-11-22 09:36 - 01515296 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2014-01-26 21:26 - 2013-12-27 19:42 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-01-26 21:26 - 2013-12-27 19:42 - 00033056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-01-26 01:00 - 2014-02-19 12:06 - 00005694 _____ () C:\Windows\setupact.log
2014-01-26 01:00 - 2014-01-26 01:00 - 00000000 _____ () C:\Windows\setuperr.log
2014-01-25 17:52 - 2014-01-25 17:52 - 00000000 ____D () C:\Users\Robin\.cache
2014-01-25 15:28 - 2014-01-26 17:48 - 03276780 _____ () C:\Users\Robin\Desktop\Schülerpraktikumsbericht.pptx

==================== One Month Modified Files and Folders =======

2014-02-19 17:42 - 2014-02-19 17:41 - 00026078 _____ () C:\Users\Robin\Desktop\FRST.txt
2014-02-19 17:41 - 2014-02-19 17:41 - 02153472 _____ (Farbar) C:\Users\Robin\Desktop\FRST64.exe
2014-02-19 17:41 - 2014-02-19 17:41 - 00000000 ____D () C:\FRST
2014-02-19 17:40 - 2013-08-05 17:20 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Skype
2014-02-19 17:25 - 2014-01-19 20:20 - 00000928 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3062181239-1702867323-3627005284-1000UA.job
2014-02-19 17:06 - 2013-12-05 14:50 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-19 16:51 - 2013-08-04 23:29 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-19 12:43 - 2013-08-24 11:43 - 00000000 ____D () C:\Program Files (x86)\File Type Advisor
2014-02-19 12:15 - 2013-12-18 20:45 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\newnext.me
2014-02-19 12:14 - 2009-07-14 05:45 - 00015760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-19 12:14 - 2009-07-14 05:45 - 00015760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-19 12:12 - 2009-07-14 18:58 - 00699394 _____ () C:\Windows\system32\perfh007.dat
2014-02-19 12:12 - 2009-07-14 18:58 - 00149534 _____ () C:\Windows\system32\perfc007.dat
2014-02-19 12:12 - 2009-07-14 06:13 - 01620346 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-19 12:07 - 2014-01-06 16:45 - 00000000 ____D () C:\Users\Robin\AppData\Local\LogMeIn Hamachi
2014-02-19 12:07 - 2013-08-17 09:34 - 00000000 ____D () C:\Users\Robin\AppData\Local\Adobe
2014-02-19 12:07 - 2013-08-05 09:42 - 00124616 _____ () C:\Users\Robin\AppData\Local\GDIPFONTCACHEV1.DAT
2014-02-19 12:06 - 2014-01-26 01:00 - 00005694 _____ () C:\Windows\setupact.log
2014-02-19 12:06 - 2013-12-05 14:50 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-19 12:06 - 2013-08-04 22:49 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-02-19 12:06 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-19 12:06 - 2009-07-14 05:45 - 05108968 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-02-18 22:40 - 2014-02-18 22:40 - 00000000 ____D () C:\Users\Robin\AppData\Local\My Games
2014-02-18 22:40 - 2013-10-21 15:35 - 00000000 ____D () C:\Users\Robin\Documents\My Games
2014-02-18 22:40 - 2013-08-05 23:41 - 00435159 _____ () C:\Windows\DirectX.log
2014-02-18 22:28 - 2014-02-18 22:28 - 00000221 _____ () C:\Users\Robin\Desktop\Sid Meier's Civilization V - Demo.url
2014-02-18 21:46 - 2013-08-07 20:08 - 00000000 ____D () C:\Users\Robin\Documents\Euro Truck Simulator 2
2014-02-18 21:23 - 2014-02-18 21:23 - 00006477 _____ () C:\Users\Robin\AppData\Local\recently-used.xbel
2014-02-18 21:23 - 2013-08-05 23:05 - 00000000 ____D () C:\Users\Robin\AppData\Local\gtk-2.0
2014-02-18 21:23 - 2013-08-05 23:03 - 00000000 ____D () C:\Users\Robin\.gimp-2.8
2014-02-18 20:25 - 2014-01-19 20:20 - 00000906 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3062181239-1702867323-3627005284-1000Core.job
2014-02-18 20:00 - 2013-08-04 22:39 - 01377138 _____ () C:\Windows\WindowsUpdate.log
2014-02-17 22:31 - 2014-02-05 18:57 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\.minecraft
2014-02-16 22:37 - 2014-02-15 19:16 - 00000000 ____D () C:\Users\Robin\Desktop\INTRO TEMPLATE BY RenttuArts
2014-02-16 19:27 - 2013-08-05 18:32 - 00007602 _____ () C:\Users\Robin\AppData\Local\Resmon.ResmonCfg
2014-02-16 17:46 - 2014-01-28 21:01 - 00000000 ___RD () C:\Users\Robin\Desktop\Aufnehmzeug
2014-02-16 17:05 - 2014-02-16 17:00 - 00000000 ____D () C:\Users\Public\Documents\Lightworks
2014-02-16 17:01 - 2014-02-16 17:01 - 00000000 ____D () C:\Users\Robin\.MCTranscodingSDK
2014-02-16 17:01 - 2013-08-04 22:37 - 00000000 ____D () C:\Users\Robin
2014-02-16 17:00 - 2014-02-16 17:00 - 00000000 ____D () C:\ProgramData\Geevs
2014-02-16 10:27 - 2013-08-05 09:37 - 00125194 _____ () C:\Windows\PFRO.log
2014-02-15 22:46 - 2014-02-15 22:44 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Systweak
2014-02-15 22:45 - 2013-12-18 20:45 - 00000000 ____D () C:\Users\Robin\AppData\Local\Mobogenie
2014-02-15 22:45 - 2013-12-18 20:45 - 00000000 ____D () C:\Program Files (x86)\Mobogenie
2014-02-15 22:45 - 2013-08-04 22:37 - 00000000 ___RD () C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-02-15 22:44 - 2014-02-15 22:44 - 00000000 ____D () C:\Users\Robin\AppData\Local\Smartbar
2014-02-15 22:44 - 2013-12-18 20:45 - 00000000 ____D () C:\Users\Robin\AppData\Local\genienext
2014-02-15 22:29 - 2014-02-15 22:19 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-02-15 22:28 - 2013-11-12 18:16 - 00000000 ____D () C:\Program Files\Adobe
2014-02-15 22:19 - 2013-08-17 09:34 - 00000000 ____D () C:\ProgramData\Adobe
2014-02-15 22:19 - 2013-08-04 23:29 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Adobe
2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Windows\System32\Tasks\SystemSockets
2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Windows\System32\Tasks\Browser Updater
2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\SimplyTech
2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Program Files\Zapp
2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Program Files (x86)\Zapp
2014-02-15 21:18 - 2014-02-15 21:18 - 00015130 _____ () C:\Users\Robin\Documents\Mein Film.wlmp
2014-02-15 20:52 - 2014-02-15 20:34 - 591803806 _____ () C:\Users\Robin\Desktop\template.avi
2014-02-15 20:52 - 2014-02-15 20:34 - 591803806 _____ () C:\Users\Robin\Desktop\A_template.avi
2014-02-15 15:29 - 2013-12-25 21:24 - 02346186 _____ () C:\Users\Robin\Desktop\TechnicLauncher.exe
2014-02-15 15:29 - 2013-10-26 18:16 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\.technic
2014-02-14 23:32 - 2014-02-09 22:33 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\vlc
2014-02-13 15:29 - 2014-02-03 18:40 - 00000000 ____D () C:\Program Files (x86)\SearchProtect
2014-02-13 15:28 - 2014-02-13 15:28 - 00000000 ____D () C:\Windows\SysWOW64\SearchProtect
2014-02-12 22:45 - 2014-02-12 22:45 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-02-12 22:45 - 2014-02-12 22:45 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-02-12 22:45 - 2014-02-12 22:45 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-02-12 22:45 - 2014-02-12 22:45 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-02-12 21:01 - 2013-12-05 14:50 - 00004104 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-02-12 21:01 - 2013-12-05 14:50 - 00003852 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-02-12 15:45 - 2013-08-27 17:24 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-02-10 19:33 - 2014-02-10 19:33 - 00000934 _____ () C:\Users\Robin\Desktop\Landwirtschafts Simulator 2013 .lnk
2014-02-10 17:26 - 2014-02-10 17:26 - 00000000 ____D () C:\Users\Robin\AppData\Local\EdgeOfReality
2014-02-10 16:08 - 2014-02-10 16:08 - 00000222 _____ () C:\Users\Robin\Desktop\Loadout.url
2014-02-09 22:33 - 2014-02-09 22:33 - 00001184 _____ () C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk
2014-02-09 22:33 - 2014-02-09 22:33 - 00000757 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-02-09 17:25 - 2014-02-09 17:25 - 00000836 _____ () C:\Users\Public\Desktop\Prime Time.lnk
2014-02-04 22:51 - 2013-08-04 23:29 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-02-04 22:51 - 2013-08-04 23:29 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-02-04 22:51 - 2013-08-04 23:29 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-02-04 16:51 - 2014-02-04 16:51 - 00003012 _____ () C:\Windows\System32\Tasks\{29949044-F7D7-4E68-B9CE-644E4CFDA5BB}
2014-02-04 06:36 - 2014-02-15 21:59 - 00033864 _____ () C:\Windows\Launcher.exe
2014-02-03 22:18 - 2013-08-05 23:55 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\uTorrent
2014-02-03 20:36 - 2014-02-03 20:36 - 00001648 _____ () C:\Users\Robin\Desktop\Euro Truck Simulator 2.lnk
2014-02-03 19:03 - 2013-08-27 17:24 - 00001040 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-02-03 19:02 - 2014-01-16 21:19 - 00080184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-02-03 19:02 - 2013-08-27 17:24 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-02-03 19:02 - 2013-08-27 17:24 - 00421704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-02-03 19:02 - 2013-08-27 17:24 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-02-03 19:02 - 2013-08-27 17:24 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-02-03 19:02 - 2013-08-27 17:24 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-02-03 18:45 - 2014-02-03 18:45 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1-click run
2014-02-03 18:44 - 2014-02-03 18:44 - 00000000 ____D () C:\2-click run
2014-02-03 18:40 - 2014-02-03 18:40 - 00000000 ____D () C:\Users\Robin\AppData\Local\SearchProtect
2014-01-30 16:38 - 2013-11-24 15:58 - 00000781 _____ () C:\Users\Robin\Desktop\TransportGigant.lnk
2014-01-30 16:10 - 2014-01-30 16:10 - 00012834 _____ () C:\Users\Robin\Desktop\Anno2070.lnk
2014-01-30 16:03 - 2013-08-30 22:11 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Virtuali
2014-01-30 16:03 - 2013-08-30 22:11 - 00000000 ____D () C:\ProgramData\Virtuali
2014-01-30 16:02 - 2014-01-30 16:02 - 00001468 _____ () C:\Users\Robin\Desktop\Flight Simulator X.lnk
2014-01-29 20:02 - 2014-01-29 20:02 - 00038960 _____ () C:\Windows\SysWOW64\RGBAcodec.dll
2014-01-27 19:49 - 2013-11-21 22:33 - 00000000 ____D () C:\Users\Robin\AppData\Local\Microsoft Games
2014-01-26 21:30 - 2013-08-04 22:49 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-01-26 17:48 - 2014-01-25 15:28 - 03276780 _____ () C:\Users\Robin\Desktop\Schülerpraktikumsbericht.pptx
2014-01-26 01:00 - 2014-01-26 01:00 - 00000000 _____ () C:\Windows\setuperr.log
2014-01-25 17:52 - 2014-01-25 17:52 - 00000000 ____D () C:\Users\Robin\.cache
2014-01-21 03:53 - 2013-11-02 10:54 - 01179576 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2014-01-21 03:53 - 2013-11-02 10:54 - 01048152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
ZeroAccess:
C:\Users\Robin\AppData\Local\Google\Desktop\Install
ZeroAccess:
C:\Program Files (x86)\Google\Desktop\Install

Some content of TEMP:
====================
C:\Users\Robin\AppData\Local\Temp\BackupSetup.exe
C:\Users\Robin\AppData\Local\Temp\Creative Cloud Helper.exe
C:\Users\Robin\AppData\Local\Temp\DownloadManager.exe
C:\Users\Robin\AppData\Local\Temp\nssCDB.exe
C:\Users\Robin\AppData\Local\Temp\nssD78.exe
C:\Users\Robin\AppData\Local\Temp\PrefJsonCpp.exe
C:\Users\Robin\AppData\Local\Temp\SearchProtectINT.exe
C:\Users\Robin\AppData\Local\Temp\sqlite3.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
ATTENTION: ====> ZeroAccess. Use DeleteJunctionsIndirectory: C:\Program Files\Windows Defender


LastRegBack: 2014-02-19 12:50

==================== End Of Log ============================
         
--- --- ---


Addition:
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-02-2014
Ran by Robin at 2014-02-19 17:42:19
Running from C:\Users\Robin\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

µTorrent (HKCU Version: 3.3.2.30488 - BitTorrent Inc.)
4Videosoft MKV Video Converter 5.0.8 (x32 Version:  - )
Adobe After Effects CC (x32 Version: 12.2.1 - Adobe Systems Incorporated)
Adobe Creative Cloud (x32 Version: 2.4.1.351 - Adobe Systems Incorporated)
Adobe Flash Player 12 ActiveX (x32 Version: 12.0.0.44 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (x32 Version: 12.0.0.44 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (Version: 3.0.868.0 - Advanced Micro Devices, Inc.)
ANNO 2070 (x32 Version: 1.0.0.0 - Ubisoft)
Apple Application Support (x32 Version: 2.3.4 - Apple Inc.)
Apple Mobile Device Support (Version: 6.1.0.13 - Apple Inc.)
Apple Software Update (x32 Version: 2.1.3.127 - Apple Inc.)
AppPublisherURL=hxxp://www.rtl-primetime.de/ 
AppVersion=1.0)
avast! Free Antivirus (x32 Version: 9.0.2013 - Avast Software)
Battlefield Heroes (x32 Version:  - EA Digital illusions)
Bonjour (Version: 3.0.0.10 - Apple Inc.)
Cinema 4D version R12 (x32 Version: R12 - Salat Production)
CL-Eye Driver (x32 Version: 5.3.0.0341 - Code Laboratories, Inc.)
Crazy Taxi (x32 Version:  - )
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (x32 Version: 4.47.1.0333 - Disc Soft Ltd)
Die Siedler 7 (x32 Version: 1.02.1221 - Ubisoft)
Die Sims™ 3 (x32 Version: 1.63.4 - Electronic Arts)
Die Sims™ 3 Into the Future (x32 Version: 21.0.150 - Electronic Arts)
Die Sims™ 3 Late Night (x32 Version: 6.0.81 - Electronic Arts)
Die Sims™ 3 Lebensfreude (x32 Version: 8.0.152 - Electronic Arts)
Die Sims™ 3 Reiseabenteuer (x32 Version: 2.0.86 - Electronic Arts)
Die Sims™ 3 Traumkarrieren (x32 Version: 4.0.87 - Electronic Arts)
Easy MP3 Cutter 3.0 (x32 Version:  - ManiacTools.com)
EPSON SX430 Series Printer Uninstall (Version:  - SEIKO EPSON Corporation)
Etron USB3.0 Host Controller (x32 Version: 0.115 - Etron Technology)
Etron USB3.0 Host Controller (x32 Version: 0.115 - Etron Technology) Hidden
Euro Truck Simulator 2 (x32 Version: 1.4.8 - SCS Software)
Euro Truck Simulator 2 v1.7.1 (DLC Going East) (x32 Version: 1.7.1 - Friends in War)
Facebook Video Calling 2.0.0.447 (x32 Version: 2.0.447 - Skype Limited)
File Type Advisor 1.0 (x32 Version:  - filetypeadvisor.com)
FileEdit (HKCU Version: 1.0.0.7 - FileEdit)
FileZilla Client 3.7.3 (x32 Version: 3.7.3 - Tim Kosse)
Fotogalerie (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Fraps (remove only) (x32 Version:  - )
Free M4a to MP3 Converter 8.0 (x32 Version:  - ManiacTools.com)
Free YouTube Download version 3.2.11.812 (x32 Version: 3.2.11.812 - DVDVideoSoft Ltd.)
FSDreamTeam GSX 1.7.9.8 (x32 Version:  - )
GeForce Experience NvStream Client Components (Version: 1.6.28 - NVIDIA Corporation) Hidden
GIGABYTE OC_GURU II (x32 Version: 1.37.0000 - GIGABYTE Technology Co.,Ltd.)
GIGABYTE OC_GURU II (x32 Version: 1.37.0000 - GIGABYTE Technology Co.,Ltd.) Hidden
GIMP 2.8.6 (Version: 2.8.6 - The GIMP Team)
Google Earth Plug-in (x32 Version: 7.1.2.2041 - Google)
Google Update Helper (x32 Version: 1.3.22.5 - Google Inc.) Hidden
Grand Theft Auto IV (x32 Version: 1.0.0013.131 - Rockstar Games Inc.) Hidden
Grand Theft Auto IV (x32 Version: 1.00.0000 - Rockstar Games)
Hear (Version:  - Joesoft)
HomepageFIX 2013 (x32 Version: Aktuelle Version - IN MEDIA KG)
ICQ 8.1 (build 6337) (HKCU Version: 8.1.6337.0 - Mail.Ru)
IndustrieGigant 2 (x32 Version:  - UIG GmbH)
InterActual Player (x32 Version:  - )
iTunes (Version: 11.0.5.5 - Apple Inc.)
Java 7 Update 51 (64-bit) (Version: 7.0.510 - Oracle)
Just Flight - Traffic X (x32 Version: 1.00.000 - Just Flight)
Landwirtschafts Simulator 2013 (x32 Version: 1.0 - GIANTS Software)
Lightworks (x32 Version: 11.5.0.0 - Lightworks)
Loadout (x32 Version:  - Edge of Reality)
LogMeIn Hamachi (x32 Version: 2.2.0.130 - LogMeIn, Inc.)
LogMeIn Hamachi (x32 Version: 2.2.0.130 - LogMeIn, Inc.) Hidden
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5 (Version: 4.5.50709 - Microsoft Corporation) Hidden
Microsoft Age of Empires II Trial Version (x32 Version:  - )
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Flight Simulator X (x32 Version: 10.0.61355.0 - Microsoft Game Studios) Hidden
Microsoft Flight Simulator X Service Pack 1 (x32 Version: 10.0.61355.0 - Microsoft Game Studios) Hidden
Microsoft Flight Simulator X Service Pack 2 (x32 Version: 10.0.61472.0 - Microsoft Game Studios)
Microsoft Games for Windows - LIVE Redistributable (x32 Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (x32 Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft XNA Framework Redistributable 4.0 (x32 Version: 4.0.20823.0 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mozilla Firefox 25.0 (x86 de) (x32 Version: 25.0 - Mozilla)
Mozilla Firefox 26.0 (x86 de) (HKCU Version: 26.0 - Mozilla)
Mozilla Maintenance Service (x32 Version: 25.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT Redists (Version: 1.0 - Sony Creative Software Inc.) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
MSXML 4.0 SP2 Parser und SDK (x32 Version: 4.20.9818.0 - Microsoft Corporation)
Notepad++ (x32 Version: 6.4.5 - Notepad++ Team)
NVIDIA 3D Vision Controller-Treiber 332.21 (Version: 332.21 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 332.21 (Version: 332.21 - NVIDIA Corporation)
NVIDIA GeForce Experience 1.8.2 (Version: 1.8.2 - NVIDIA Corporation)
NVIDIA Grafiktreiber 332.21 (Version: 332.21 - NVIDIA Corporation)
NVIDIA HD-Audiotreiber 1.3.30.1 (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.142.992 - NVIDIA Corporation) Hidden
NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.0725 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.13.0725 (Version: 9.13.0725 - NVIDIA Corporation)
NVIDIA ShadowPlay 11.10.11 (Version: 11.10.11 - NVIDIA Corporation) Hidden
NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3221 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 332.21 (Version: 332.21 - NVIDIA Corporation) Hidden
NVIDIA Update 11.10.11 (Version: 11.10.11 - NVIDIA Corporation) Hidden
NVIDIA Update Core (Version: 11.10.11 - NVIDIA Corporation) Hidden
NVIDIA Virtual Audio 1.2.20 (Version: 1.2.20 - NVIDIA Corporation)
Origin (x32 Version: 9.1.10.2728 - Electronic Arts, Inc.)
outobox (Version: 2013.12.07.011955 - outobox) <==== ATTENTION
Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Photo Gallery (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Prime Time (x32 Version:  - RTL Playtainment 
Prison Architect (x32 Version:  - Introversion Software)
PunkBuster Services (x32 Version: 0.990 - Even Balance, Inc.)
QuickTime (x32 Version: 7.74.80.86 - Apple Inc.)
RCT3 Soaked (x32 Version: 1.00.000 - )
Realtek Ethernet Controller Driver (x32 Version: 7.44.421.2011 - Realtek)
Realtek High Definition Audio Driver (x32 Version: 6.0.1.6873 - Realtek Semiconductor Corp.)
ReelSmart Motion Blur 4, After Effects-compatible plugin set (x32 Version:  - )
RollerCoaster Tycoon 3 (x32 Version: 1.00.000 - )
Rust (x32 Version:  - Facepunch Studios)
Search Protect (x32 Version: 2.10.20.64 - Conduit) <==== ATTENTION
SHIELD Streaming (Version: 1.7.306 - NVIDIA Corporation) Hidden
Shopop (x32 Version: 10.203.68.14274 - My Pop Shop Ltd.) <==== ATTENTION
Sid Meier's Civilization V - Demo (x32 Version:  - Firaxis Games)
SimCity™ (x32 Version: 1.0.0.0 - Electronic Arts)
Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.)
Source SDK Base 2007 (x32 Version:  - Valve)
Steam (x32 Version: 1.0.0.0 - Valve Corporation)
TeamSpeak 3 Client (Version: 3.0.11 - TeamSpeak Systems GmbH)
TeamViewer 8 (x32 Version: 8.0.20202 - TeamViewer)
TG-MOD (x32 Version: 0.32 - -)
Train Simulator 2014 (x32 Version:  - RailSimulator.com)
TransportGigant (x32 Version: 1.3.0 - JoWooD Productions Software AG)
TransportGigant: Down Under (x32 Version: 2.10 - JoWooD Productions Software AG)
Ubisoft Game Launcher (x32 Version: 1.0.0.0 - UBISOFT)
Unity Web Player (HKCU Version:  - Unity Technologies ApS)
Update for Microsoft .NET Framework 4.5 (KB2750147) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4.5 (KB2805221) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4.5 (KB2805226) (x32 Version: 1 - Microsoft Corporation)
Vegas Pro 12.0 (64-bit) (Version: 12.0.670 - Sony)
VLC media player 2.1.3 (Version: 2.1.3 - VideoLAN)
Waterfox 26.0 (x64 en-US) (Version: 26.0 - Mozilla)
Windows Live Communications Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
WinRAR 4.20 (64-Bit) (Version: 4.20.0 - win.rar GmbH)
Wireless Systems Manager (x32 Version: 4.0.85 - Sennheiser electronic)
World of Tanks (x32 Version:  - Wargaming.net)
World of Warplanes (x32 Version:  - Wargaming.net)
World Series Of Poker  (x32 Version:  - )
WorldPainter 1.5.0 (Version: 1.5.0 - pepsoft.org)
Zapp 5.7 (x32 Version: 5.7 - Zapp)

==================== Restore Points  =========================


==================== Hosts content: ==========================

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {03873767-33A9-471F-B34A-5449C8182409} - System32\Tasks\{97B51F7E-61B9-4818-B97D-DA0C55020521} => D:\Program Files (x86)\Skype\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.)
Task: {05524248-BAAE-45F2-B7E8-1FDC7B75D8E1} - System32\Tasks\{5576FB1A-EA81-4DB0-9370-2EB35F3519C8} => C:\Users\Robin\Desktop\ig2_addon_patch21_de(1).exe
Task: {227C430F-E696-498D-B219-8A42D828ABAE} - System32\Tasks\{4DFC705A-3CA5-4287-BE1E-395DAEF79BD6} => C:\Users\Robin\Desktop\ig2_addon_patch21_de(1).exe
Task: {229E415C-E81E-4FC4-8F5C-3AA21EF0E243} - System32\Tasks\{56D1DA53-B247-4305-994B-D9BF5130DE61} => D:\Program Files (x86)\TransportGigant\transportgiant.exe [2004-10-28] (JoWooD Productions Software AG)
Task: {24842094-8928-485B-9AF9-F6A11550677E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-02-04] (Adobe Systems Incorporated)
Task: {248D936E-C7FE-4368-B2C0-68030AC26A38} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3062181239-1702867323-3627005284-1000UA => C:\Users\Robin\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-01-19] (Facebook Inc.)
Task: {249DE304-F23B-42B4-9D30-D20BF2AF2653} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-05] (Google Inc.)
Task: {2E09AC7E-AB29-4BA1-812F-CDAE097A8066} - System32\Tasks\Browser Updater\Zapp Browser Updater => C:\Program Files (x86)\Zapp\tbupdater.exe
Task: {393A9A7A-118B-4E59-9B98-E9629F2D7843} - System32\Tasks\{7B17E059-F7D4-4361-A07B-E745123DC8D5} => D:\Program Files (x86)\TransportGigant\transportgiant.exe [2004-10-28] (JoWooD Productions Software AG)
Task: {57604AB5-7B2B-44E2-8B33-F69933632486} - System32\Tasks\avast! Emergency Update => D:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-02-03] (AVAST Software)
Task: {5F165A9D-2B23-4018-8E44-1A5EC506E4C4} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] ()
Task: {77C23E79-380E-4E29-BCB6-370909E92EC8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-12-05] (Google Inc.)
Task: {787437D7-B900-44B4-9EDF-EA1B10001115} - System32\Tasks\{B79F3902-4091-4930-A573-E4A090A0A7E1} => C:\Users\Robin\Desktop\ig2_addon_patch21_de(1).exe
Task: {7CD884B1-F48C-4C5E-AF4B-35B543E76346} - System32\Tasks\{A5A1D7B4-1739-4954-815E-E58981842E7D} => D:\Program Files (x86)\Skype\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.)
Task: {81FA4FB1-64A2-4B5B-85DD-CFEBE1D21B5E} - System32\Tasks\FileAdvisorCheck => C:\Program Files (x86)\File Type Advisor\file-type-advisor.exe [2013-07-12] (filetypeadvisor.com                                         )
Task: {87E2AF4D-A960-414F-A871-8FBD259E947E} - System32\Tasks\{B39D9B38-9D41-410C-B032-985E9205FFA9} => C:\Users\Robin\Desktop\ig2_addon_patch21_de(1).exe
Task: {8C9786BD-E15A-4422-BC50-C4A717186593} - System32\Tasks\{DEA2DC23-3805-47F4-A4CF-509889A050F7} => D:\Program Files (x86)\TransportGigant\transportgiant.exe [2004-10-28] (JoWooD Productions Software AG)
Task: {94ACFFF0-2504-433F-A8B9-510C39FFE683} - System32\Tasks\{0B0793EA-DF9D-4F35-9ABB-ECA9F8E6E909} => C:\Users\Robin\Desktop\ig2_addon_patch21_de(1).exe
Task: {9BEAD541-DD5D-4E2F-962A-62872BCBC274} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-3062181239-1702867323-3627005284-1000Core => C:\Users\Robin\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-01-19] (Facebook Inc.)
Task: {AF5F6EFE-7E50-4979-BC7D-3AE1597D9B73} - System32\Tasks\{3FAB98F2-BDEC-47EE-A57D-51285D12C184} => D:\Program Files (x86)\TransportGigant\transportgiant.exe [2004-10-28] (JoWooD Productions Software AG)
Task: {B0338402-4979-4D02-988C-04D25ABA9BB9} - System32\Tasks\{741CDDD5-0EFC-4FEA-800B-EF6E75535219} => D:\Program Files (x86)\Skype\Phone\Skype.exe [2013-11-14] (Skype Technologies S.A.)
Task: {BCBD4C9C-7FD0-4946-9169-CFC8350A1FCC} - System32\Tasks\FileAdvisorUpdate => C:\Program Files (x86)\File Type Advisor\fileadvisor.exe [2013-07-12] (File Type Advisor)
Task: {C3A401A9-D6A8-43F0-BA39-D190CE281869} - System32\Tasks\{BBBD1780-C0FF-4C5C-B2D8-7DB612F06A3D} => C:\Program Files (x86)\Terraria\Terraria.exe
Task: {CB52A3AF-8201-4406-B194-13FDC5865C31} - System32\Tasks\{29949044-F7D7-4E68-B9CE-644E4CFDA5BB} => D:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe [2013-08-17] (Sony DADC Austria AG)
Task: {D542AB36-D07C-4D3F-9A5E-F4302F4E4B52} - System32\Tasks\{4530D85B-3038-4F3A-A223-2608EB0CCCEE} => C:\Users\Robin\Desktop\ig2_addon_patch21_de(1).exe
Task: {F1B6A710-99D9-499E-986D-28307E626B2B} - System32\Tasks\{88AA7E58-581B-4365-B920-437A052D9500} => C:\Users\Robin\Desktop\ig2_addon_patch21_de(1).exe
Task: {FEC68702-49D6-4691-808C-EE3AA92F35AA} - System32\Tasks\{FA1A5B05-1D9B-4464-B2F7-CC8D12CB791A} => D:\Program Files (x86)\TransportGigant\transportgiant.exe [2004-10-28] (JoWooD Productions Software AG)
Task: {FF36824C-7BCA-4FD1-A209-0A32FD4A0EB0} - System32\Tasks\SystemSockets\SystemSockets => C:\Program Files (x86)\Zapp\WConnectorProductivity.exe [2014-01-09] ()
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3062181239-1702867323-3627005284-1000Core.job => C:\Users\Robin\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3062181239-1702867323-3627005284-1000UA.job => C:\Users\Robin\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2013-08-04 22:49 - 2013-12-19 19:53 - 00117536 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2010-01-30 01:40 - 2010-01-30 01:40 - 04254560 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-01-02 15:42 - 2010-01-02 15:42 - 00098304 _____ () D:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2014-02-15 21:59 - 2014-01-09 08:16 - 00034376 _____ () C:\Program Files (x86)\Zapp\WConnectorProductivity.exe
2013-10-09 23:11 - 2013-10-09 23:20 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-01-16 21:16 - 2011-11-28 20:47 - 03174024 _____ () D:\Program Files\Hear\Hear.exe
2014-01-05 11:34 - 2014-01-21 03:56 - 00093472 _____ () C:\Program Files\NVIDIA Corporation\ShadowPlay\gamecaster64.dll
2014-01-05 11:34 - 2014-01-21 03:56 - 00874784 _____ () C:\Program Files\NVIDIA Corporation\ShadowPlay\twitchsdk64.dll
2014-01-15 11:02 - 2014-01-15 11:02 - 04697456 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncV1\CoreSync.exe
2014-02-17 19:01 - 2014-02-17 19:01 - 18204416 _____ () D:\Program Files (x86)\Steam\steamapps\common\rust\rust.exe
2014-02-05 21:03 - 2013-12-07 19:09 - 07350272 _____ () D:\Program Files\Waterfox\mozjs.dll
2013-12-11 13:51 - 2013-12-11 13:51 - 22332808 _____ () C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll
2014-02-19 12:08 - 2014-02-19 09:01 - 02181120 _____ () D:\Program Files\AVAST Software\Avast\defs\14021900\algo.dll
2013-08-06 07:51 - 2013-08-06 07:51 - 00851456 _____ () C:\Users\Robin\AppData\Roaming\ICQM\ICQ\dll\YLUSBTEL.dll
2013-04-21 20:44 - 2013-04-21 20:44 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2013-04-21 20:44 - 2013-04-21 20:44 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2014-01-08 11:51 - 2013-12-12 23:19 - 00142848 _____ () D:\Program Files (x86)\Steam\libavresample-1.dll
2014-01-08 11:51 - 2013-11-05 02:12 - 00890592 _____ () D:\Program Files (x86)\Steam\libavutil-52.dll
2013-07-01 07:20 - 2014-01-11 00:33 - 00717312 _____ () D:\Program Files (x86)\Steam\SDL2.dll
2013-07-26 13:46 - 2014-01-27 20:02 - 01138088 _____ () D:\Program Files (x86)\Steam\bin\chromehtml.DLL
2013-07-15 13:32 - 2014-01-11 00:33 - 20625832 _____ () D:\Program Files (x86)\Steam\bin\libcef.dll
2013-06-14 14:49 - 2013-06-15 00:49 - 01100800 _____ () D:\Program Files (x86)\Steam\bin\avcodec-53.dll
2013-06-14 14:49 - 2013-06-15 00:49 - 00124416 _____ () D:\Program Files (x86)\Steam\bin\avutil-51.dll
2013-06-14 14:49 - 2013-06-15 00:49 - 00192000 _____ () D:\Program Files (x86)\Steam\bin\avformat-53.dll
2010-01-30 01:41 - 2010-01-30 01:41 - 04254560 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2013-12-31 16:40 - 2013-12-31 16:40 - 00034864 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Core.dll
2013-12-31 16:40 - 2013-12-31 16:40 - 00064048 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\srau.dll
2013-12-31 16:40 - 2013-12-31 16:40 - 00150576 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Utilities.dll
2013-12-31 16:40 - 2013-12-31 16:40 - 00112688 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\Smartbar.Resources.HistoryAndStatsWrapper.dll
2013-12-31 16:40 - 2013-12-31 16:40 - 02151984 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\Smartbar.GUI.MainClient.dll
2013-12-31 16:40 - 2013-12-31 16:40 - 00055856 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\spbl.dll
2013-12-31 16:40 - 2013-12-31 16:40 - 00013360 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\siem.dll
2013-12-31 16:40 - 2013-12-31 16:40 - 00048688 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\sppsm.dll
2013-12-31 16:40 - 2013-12-31 16:40 - 00728112 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\Smartbar.GUI.Controls.dll
2013-12-31 16:40 - 2013-12-31 16:40 - 00081968 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\Smartbar.GUI.Docking.dll
2013-12-31 16:40 - 2013-12-31 16:40 - 00014384 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.BusinessEntities.dll
2013-12-31 16:40 - 2013-12-31 16:40 - 00017456 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\Smartbar.Personalization.Common.dll
2013-12-31 16:40 - 2013-12-31 16:40 - 00031280 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\srut.dll
2013-12-31 16:40 - 2013-12-31 16:40 - 00020528 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\srsbs.dll
2013-12-31 16:40 - 2013-12-31 16:40 - 00057392 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\Smartbar.Infrastructure.Plugins.InternetExplorerLocalPlugin.dll
2013-12-31 16:40 - 2013-12-31 16:40 - 00014384 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\srpdm.dll
2013-12-31 16:40 - 2013-12-31 16:40 - 00014384 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\sgml.dll
2013-12-31 16:40 - 2013-12-31 16:40 - 00053296 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\Smartbar.Resources.LanguageSettings.dll
2013-12-31 16:38 - 2013-12-31 16:38 - 00048176 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\MACTrackBarLib.dll
2013-12-31 16:38 - 2013-12-31 16:38 - 00026160 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\de\Smartbar.Resources.LanguageSettings.resources.dll
2013-12-31 16:40 - 2013-12-31 16:40 - 00025648 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\Smartbar.Resources.SocialNetsSharer.dll
2013-12-31 16:40 - 2013-12-31 16:40 - 00248368 _____ () C:\Users\Robin\AppData\Local\Smartbar\Application\srns.dll
2014-02-11 15:09 - 2014-02-11 15:09 - 32733080 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libcef.dll
2013-08-07 20:25 - 2013-08-07 20:25 - 00093696 _____ () D:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
2013-11-23 13:20 - 2013-11-23 13:20 - 19336120 _____ () D:\Program Files\AVAST Software\Avast\libcef.dll
2014-02-11 15:09 - 2014-02-11 15:09 - 00742808 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libglesv2.dll
2014-02-11 15:09 - 2014-02-11 15:09 - 00136600 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libegl.dll

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\ProgramData\TEMP:74603393

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Hamachi2Svc => ""="Service"

==================== Disabled items from MSCONFIG ==============


==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (02/19/2014 00:07:42 PM) (Source: Steam Client Service) (User: )
Description: Error: Failed to poke open firewall

Error: (02/18/2014 09:23:41 PM) (Source: Application Hang) (User: )
Description: Programm gimp-2.8.exe, Version 2.8.6.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 2030

Startzeit: 01cf2ce4d4eda417

Endzeit: 3

Anwendungspfad: D:\Program Files\GIMP 2\bin\gimp-2.8.exe

Berichts-ID: 8cfb5941-98da-11e3-aa71-bc5ff48acc01

Error: (02/18/2014 06:02:32 PM) (Source: Steam Client Service) (User: )
Description: Error: Failed to poke open firewall

Error: (02/18/2014 05:22:30 PM) (Source: Steam Client Service) (User: )
Description: Error: Failed to poke open firewall

Error: (02/17/2014 10:03:30 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: GTAIV.exe, Version: 1.0.7.0, Zeitstempel: 0x4bd9efbe
Name des fehlerhaften Moduls: GTAIV.exe, Version: 1.0.7.0, Zeitstempel: 0x4bd9efbe
Ausnahmecode: 0xc0000005
Fehleroffset: 0x001a9346
ID des fehlerhaften Prozesses: 0x22ac
Startzeit der fehlerhaften Anwendung: 0xGTAIV.exe0
Pfad der fehlerhaften Anwendung: GTAIV.exe1
Pfad des fehlerhaften Moduls: GTAIV.exe2
Berichtskennung: GTAIV.exe3

Error: (02/17/2014 10:03:29 PM) (Source: .NET Runtime) (User: )
Description: Application: GTAIV.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: exception code c0000005, exception address 01479346
Stack:

Error: (02/17/2014 07:01:06 PM) (Source: Steam Client Service) (User: )
Description: Error: Failed to poke open firewall

Error: (02/16/2014 02:11:46 PM) (Source: Steam Client Service) (User: )
Description: Error: Failed to poke open firewall

Error: (02/16/2014 02:09:00 PM) (Source: Application Hang) (User: )
Description: Programm icq.exe, Version 8.1.6337.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 890

Startzeit: 01cf2af9449b775f

Endzeit: 22

Anwendungspfad: C:\Users\Robin\AppData\Roaming\ICQM\icq.exe

Berichts-ID:

Error: (02/16/2014 10:28:06 AM) (Source: Steam Client Service) (User: )
Description: Error: Failed to poke open firewall


System errors:
=============
Error: (02/19/2014 01:09:57 PM) (Source: volsnap) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.

Error: (02/19/2014 00:07:00 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuche-Ressourcenveröffentlichung" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: 
%%-2147024891

Error: (02/19/2014 00:07:00 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Funktionssuche-Ressourcenveröffentlichung" wurde mit folgendem Fehler beendet: 
%%-2147024891

Error: (02/19/2014 00:07:00 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuche-Ressourcenveröffentlichung" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: 
%%-2147024891

Error: (02/19/2014 00:07:00 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Funktionssuche-Ressourcenveröffentlichung" wurde mit folgendem Fehler beendet: 
%%-2147024891

Error: (02/19/2014 00:06:53 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Computerbrowser" wurde mit folgendem Fehler beendet: 
%%1060

Error: (02/19/2014 00:06:51 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "WinkHandler" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (02/19/2014 00:06:48 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "IPsec-Richtlinien-Agent" ist von folgendem Dienst abhängig: BFE. Dieser Dienst ist eventuell nicht installiert.

Error: (02/19/2014 00:06:48 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "IKE- und AuthIP IPsec-Schlüsselerstellungsmodule" ist von folgendem Dienst abhängig: BFE. Dieser Dienst ist eventuell nicht installiert.

Error: (02/18/2014 07:00:29 PM) (Source: volsnap) (User: )
Description: Die Schattenkopien von Volume "C:" wurden abgebrochen, weil der Schattenkopiespeicher nicht auf ein benutzerdefiniertes Limit vergrößert werden konnte.


Microsoft Office Sessions:
=========================
Error: (02/19/2014 00:07:42 PM) (Source: Steam Client Service)(User: )
Description: Failed to poke open firewall

Error: (02/18/2014 09:23:41 PM) (Source: Application Hang)(User: )
Description: gimp-2.8.exe2.8.6.0203001cf2ce4d4eda4173D:\Program Files\GIMP 2\bin\gimp-2.8.exe8cfb5941-98da-11e3-aa71-bc5ff48acc01

Error: (02/18/2014 06:02:32 PM) (Source: Steam Client Service)(User: )
Description: Failed to poke open firewall

Error: (02/18/2014 05:22:30 PM) (Source: Steam Client Service)(User: )
Description: Failed to poke open firewall

Error: (02/17/2014 10:03:30 PM) (Source: Application Error)(User: )
Description: GTAIV.exe1.0.7.04bd9efbeGTAIV.exe1.0.7.04bd9efbec0000005001a934622ac01cf2c22d7738429D:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV\GTAIV.exeD:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV\GTAIV.exef39f8df8-9816-11e3-82ae-bc5ff48acc01

Error: (02/17/2014 10:03:29 PM) (Source: .NET Runtime)(User: )
Description: Application: GTAIV.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: exception code c0000005, exception address 01479346
Stack:

Error: (02/17/2014 07:01:06 PM) (Source: Steam Client Service)(User: )
Description: Failed to poke open firewall

Error: (02/16/2014 02:11:46 PM) (Source: Steam Client Service)(User: )
Description: Failed to poke open firewall

Error: (02/16/2014 02:09:00 PM) (Source: Application Hang)(User: )
Description: icq.exe8.1.6337.089001cf2af9449b775f22C:\Users\Robin\AppData\Roaming\ICQM\icq.exe

Error: (02/16/2014 10:28:06 AM) (Source: Steam Client Service)(User: )
Description: Failed to poke open firewall


==================== Memory info =========================== 

Percentage of memory in use: 42%
Total physical RAM: 8148.74 MB
Available physical RAM: 4683.84 MB
Total Pagefile: 16295.68 MB
Available Pagefile: 10368.85 MB
Total Virtual: 8192 MB
Available Virtual: 8191.79 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:55.8 GB) (Free:4.92 GB) NTFS
Drive d: (Speicherpaltte) (Fixed) (Total:465.76 GB) (Free:245.95 GB) NTFS
Drive f: (Prime Time) (CDROM) (Total:0.65 GB) (Free:0 GB) CDFS
Drive g: (Volume) (Fixed) (Total:1862.89 GB) (Free:1601.87 GB) NTFS
Drive h: (LS2013DE) (CDROM) (Total:1.36 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 56 GB) (Disk ID: 57D4B197)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=56 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 8F2F8149)
Partition 1: (Active) - (Size=466 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (Size: 1863 GB) (Disk ID: 331A92D7)

Partition: GPT Partition Type
==================== End Of Log ============================
         
__________________

Alt 20.02.2014, 14:17   #4
schrauber
/// the machine
/// TB-Ausbilder
 

browser.newtab.url ändert sich selbstständig auf "search.conduit.com" - Standard

browser.newtab.url ändert sich selbstständig auf "search.conduit.com"



hi,

Scan mit Combofix
WARNUNG an die MITLESER:
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 20.02.2014, 16:14   #5
Robin0308
 
browser.newtab.url ändert sich selbstständig auf "search.conduit.com" - Standard

browser.newtab.url ändert sich selbstständig auf "search.conduit.com"



hi, hab hier die Logfile bzw. die Combofix.txt:
Code:
ATTFilter
ComboFix 14-02-19.01 - Robin 20.02.2014  16:05:53.2.6 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.8149.6689 [GMT 1:00]
ausgeführt von:: c:\users\Robin\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((   Dateien erstellt von 2014-01-20 bis 2014-02-20  ))))))))))))))))))))))))))))))
.
.
2014-02-20 15:09 . 2014-02-20 15:09	--------	d-----w-	c:\users\Default\AppData\Local\temp
2014-02-19 16:41 . 2014-02-19 16:42	--------	d-----w-	C:\FRST
2014-02-18 21:40 . 2014-02-18 21:40	--------	d-----w-	c:\users\Robin\AppData\Local\My Games
2014-02-16 16:01 . 2014-02-16 16:01	--------	d-----w-	c:\users\Robin\.MCTranscodingSDK
2014-02-16 16:00 . 2014-02-16 16:00	--------	d-----w-	c:\programdata\Geevs
2014-02-15 21:44 . 2014-02-15 21:44	--------	d-----w-	c:\users\Robin\AppData\Local\Smartbar
2014-02-15 21:44 . 2014-02-15 21:46	--------	d-----w-	c:\users\Robin\AppData\Roaming\Systweak
2014-02-15 21:44 . 2013-08-22 17:36	20312	----a-w-	c:\windows\system32\roboot64.exe
2014-02-15 21:19 . 2014-02-15 21:29	--------	d-----w-	c:\program files\Common Files\Adobe
2014-02-15 20:59 . 2014-02-15 20:59	--------	d-----w-	c:\program files\Zapp
2014-02-15 20:59 . 2014-02-15 20:59	--------	d-----w-	c:\users\Robin\AppData\Roaming\SimplyTech
2014-02-15 20:59 . 2014-02-15 20:59	--------	d-----w-	c:\program files (x86)\Zapp
2014-02-15 20:59 . 2014-02-04 05:36	33864	----a-w-	c:\windows\Launcher.exe
2014-02-13 14:28 . 2014-02-13 14:28	--------	d-----w-	c:\windows\SysWow64\SearchProtect
2014-02-12 21:45 . 2014-02-12 21:45	312744	----a-w-	c:\windows\system32\javaws.exe
2014-02-12 21:45 . 2014-02-12 21:45	108968	----a-w-	c:\windows\system32\WindowsAccessBridge-64.dll
2014-02-12 21:45 . 2014-02-12 21:45	189352	----a-w-	c:\windows\system32\javaw.exe
2014-02-12 21:45 . 2014-02-12 21:45	189352	----a-w-	c:\windows\system32\java.exe
2014-02-10 16:26 . 2014-02-10 16:26	--------	d-----w-	c:\users\Robin\AppData\Local\EdgeOfReality
2014-02-09 21:33 . 2014-02-14 22:32	--------	d-----w-	c:\users\Robin\AppData\Roaming\vlc
2014-02-05 17:57 . 2014-02-17 21:31	--------	d-----w-	c:\users\Robin\AppData\Roaming\.minecraft
2014-02-03 17:44 . 2014-02-03 17:44	--------	d-----w-	C:\2-click run
2014-02-03 17:40 . 2014-02-03 17:40	--------	d-----w-	c:\users\Robin\AppData\Local\SearchProtect
2014-01-29 19:02 . 2014-01-29 19:02	38960	----a-w-	c:\windows\SysWow64\RGBAcodec.dll
2014-01-26 20:26 . 2013-12-27 18:42	39200	----a-w-	c:\windows\system32\drivers\nvvad64v.sys
2014-01-26 20:26 . 2013-12-27 18:42	33056	----a-w-	c:\windows\SysWow64\nvaudcap32v.dll
2014-01-25 16:52 . 2014-01-25 16:52	--------	d-----w-	c:\users\Robin\.fontconfig
2014-01-25 16:52 . 2014-01-25 16:52	--------	d-----w-	c:\users\Robin\.cache
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-02-04 21:51 . 2013-08-04 22:29	71048	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-02-04 21:51 . 2013-08-04 22:29	692616	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2014-02-03 18:02 . 2014-01-16 20:19	80184	----a-w-	c:\windows\system32\drivers\aswstm.sys
2014-02-03 18:02 . 2013-08-27 16:24	421704	----a-w-	c:\windows\system32\drivers\aswSP.sys
2014-02-03 18:02 . 2013-08-27 16:24	78648	----a-w-	c:\windows\system32\drivers\aswMonFlt.sys
2014-02-03 18:02 . 2013-08-27 16:24	334136	----a-w-	c:\windows\system32\aswBoot.exe
2014-02-03 18:02 . 2013-08-27 16:24	1038072	----a-w-	c:\windows\system32\drivers\aswSnx.sys
2014-02-03 18:02 . 2013-08-27 16:24	43152	----a-w-	c:\windows\avastSS.scr
2014-01-21 02:53 . 2013-11-02 09:54	1048152	----a-w-	c:\windows\SysWow64\nvspcap.dll
2014-01-21 02:53 . 2013-11-02 09:54	1179576	----a-w-	c:\windows\system32\nvspcap64.dll
2014-01-16 20:19 . 2013-08-27 16:24	207904	----a-w-	c:\windows\system32\drivers\aswVmm.sys
2013-12-27 18:42 . 2013-08-04 22:12	35104	----a-w-	c:\windows\system32\nvaudcap64v.dll
2013-12-19 20:33 . 2013-08-04 22:19	18310112	----a-w-	c:\windows\system32\nvwgf2umx.dll
2013-12-19 20:33 . 2013-08-04 22:19	15877216	----a-w-	c:\windows\SysWow64\nvwgf2um.dll
2013-12-19 20:33 . 2013-08-04 21:49	61216	----a-w-	c:\windows\system32\OpenCL.dll
2013-12-19 20:33 . 2013-08-04 21:49	53024	----a-w-	c:\windows\SysWow64\OpenCL.dll
2013-12-19 20:33 . 2013-08-04 21:48	1436528	----a-w-	c:\windows\system32\nvumdshimx.dll
2013-12-19 20:33 . 2013-08-04 21:48	15230352	----a-w-	c:\windows\SysWow64\nvd3dum.dll
2013-12-19 20:33 . 2013-08-04 21:48	3071656	----a-w-	c:\windows\system32\nvapi64.dll
2013-12-19 20:33 . 2013-08-04 21:48	2698272	----a-w-	c:\windows\SysWow64\nvapi.dll
2013-12-19 18:53 . 2013-08-04 21:49	6671648	----a-w-	c:\windows\system32\nvcpl.dll
2013-12-19 18:53 . 2013-08-04 21:49	3490080	----a-w-	c:\windows\system32\nvsvc64.dll
2013-12-19 18:53 . 2013-08-04 21:49	922912	----a-w-	c:\windows\system32\nvvsvc.exe
2013-12-19 18:53 . 2013-08-04 21:49	63776	----a-w-	c:\windows\system32\nvshext.dll
2013-12-19 18:53 . 2013-08-04 21:49	386336	----a-w-	c:\windows\system32\nvmctray.dll
2013-12-19 18:53 . 2013-08-04 21:49	2559776	----a-w-	c:\windows\system32\nvsvcr.dll
2013-12-19 11:20 . 2013-12-19 11:20	590112	----a-w-	c:\windows\SysWow64\nvStreaming.exe
2013-12-19 05:01 . 2013-08-04 21:49	3539040	----a-w-	c:\windows\system32\nvcoproc.bin
2013-12-04 19:32 . 2013-10-09 22:15	282296	----a-w-	c:\windows\SysWow64\PnkBstrB.xtr
2013-12-04 19:32 . 2013-10-09 22:12	282296	----a-w-	c:\windows\SysWow64\PnkBstrB.exe
2013-12-04 19:31 . 2013-10-09 22:12	270240	----a-w-	c:\windows\SysWow64\PnkBstrB.ex0
2013-11-24 14:58 . 2013-11-24 14:58	10240	----a-r-	c:\users\Robin\AppData\Roaming\Microsoft\Installer\{BAC3B914-9A96-4097-A5C7-7BF0CAD679D3}\IconBAC3B9141.exe
2013-11-24 14:58 . 2013-11-24 14:58	10240	----a-r-	c:\users\Robin\AppData\Roaming\Microsoft\Installer\{BAC3B914-9A96-4097-A5C7-7BF0CAD679D3}\IconBAC3B914.exe
2013-11-23 12:20 . 2013-08-27 16:24	92544	----a-w-	c:\windows\system32\drivers\aswRdr2.sys
2013-11-23 12:20 . 2013-08-27 16:24	65776	----a-w-	c:\windows\system32\drivers\aswRvrt.sys
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{14264a21-01fa-455f-a9c4-7c8b3d82b6f6}]
2014-02-05 06:38	1103432	----a-w-	c:\program files (x86)\Zapp\IE\Zapp.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{31ad400d-1b06-4e33-a59a-90c2c140cba0}]
2010-11-05 01:58	297808	----a-w-	c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{14264a21-01fa-455f-a9c4-7c8b3d82b6f6}"= "c:\program files (x86)\Zapp\IE\Zapp.dll" [2014-02-05 1103432]
.
[HKEY_CLASSES_ROOT\clsid\{14264a21-01fa-455f-a9c4-7c8b3d82b6f6}]
[HKEY_CLASSES_ROOT\wtb.Band.1]
[HKEY_CLASSES_ROOT\TypeLib\{8ff7f225-ef13-4714-a630-951a331d8189}]
[HKEY_CLASSES_ROOT\wtb.Band]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="d:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2013-03-14 3672640]
"icq"="c:\users\Robin\AppData\Roaming\ICQM\icq.exe" [2013-08-06 28698984]
"Steam"="d:\program files (x86)\Steam\steam.exe" [2014-02-18 1822400]
"EPLTarget\P0000000000000000"="c:\windows\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE" [2012-02-29 283232]
"Skype"="d:\program files (x86)\Skype\Phone\Skype.exe" [2013-11-14 20584608]
"EPLTarget\P0000000000000001"="c:\windows\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE" [2012-02-29 283232]
"Browser Infrastructure Helper"="c:\users\Robin\AppData\Local\Smartbar\Application\Shopop.exe" [2013-12-31 21040]
"NextLive"="c:\users\Robin\AppData\Roaming\newnext.me\nengine.dll" [2013-11-14 1283584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-05-11 958576]
"BCSSync"="d:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-04-21 59720]
"iTunesHelper"="d:\program files (x86)\iTunes\iTunesHelper.exe" [2013-08-16 152392]
"QuickTime Task"="d:\program files (x86)\QuickTime\QTTask.exe" [2013-05-01 421888]
"Adobe Creative Cloud"="c:\program files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" [2014-02-11 2239376]
"AvastUI.exe"="d:\program files\AVAST Software\Avast\AvastUI.exe" [2014-02-03 3767096]
"LogMeIn Hamachi Ui"="d:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2014-02-04 3813712]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
GIGABYTE OC_GURU.lnk - c:\program files (x86)\GIGABYTE\GIGABYTE OC_GURU II\OC_GURU.exe [2013-3-1 21946368]
Hear.lnk - d:\program files\Hear\Hear.exe [2014-1-16 3174024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer1"=wdmaud.drv
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 CltMngSvc;Search Protect by Conduit Service;c:\progra~2\SearchProtect\Main\bin\CltMngSvc.exe;c:\progra~2\SearchProtect\Main\bin\CltMngSvc.exe [x]
R2 SkypeUpdate;Skype Updater;d:\program files (x86)\Skype\Updater\Updater.exe;d:\program files (x86)\Skype\Updater\Updater.exe [x]
R2 WinkHandler;WinkHandler;c:\program files (x86)\Iminent\WinkHandler.exe;c:\program files (x86)\Iminent\WinkHandler.exe [x]
R3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
R3 GPCIDrv;GPCIDrv;c:\program files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys;c:\program files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WSDScan;WSD-Scanunterstützung durch UMB;c:\windows\system32\DRIVERS\WSDScan.sys;c:\windows\SYSNATIVE\DRIVERS\WSDScan.sys [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;d:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;d:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
S2 NvNetworkService;NVIDIA Network Service;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe;c:\program files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [x]
S2 NvStreamSvc;NVIDIA Streamer Service;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe;c:\program files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [x]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe;c:\program files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [x]
S2 TeamViewer8;TeamViewer 8;d:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe;d:\program files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [x]
S3 EtronHub3;Etron USB 3.0 Extensible Hub Driver;c:\windows\system32\Drivers\EtronHub3.sys;c:\windows\SYSNATIVE\Drivers\EtronHub3.sys [x]
S3 EtronXHCI;Etron USB 3.0 Extensible Host Controller Driver;c:\windows\system32\Drivers\EtronXHCI.sys;c:\windows\SYSNATIVE\Drivers\EtronXHCI.sys [x]
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x]
S3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad64v.sys;c:\windows\SYSNATIVE\drivers\nvvad64v.sys [x]
S3 REN2CAP_DRIVER;Hear;c:\windows\system32\drivers\ren2cap.sys;c:\windows\SYSNATIVE\drivers\ren2cap.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2014-02-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-04 21:51]
.
2014-02-19 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3062181239-1702867323-3627005284-1000Core.job
- c:\users\Robin\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-01-19 19:20]
.
2014-02-19 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3062181239-1702867323-3627005284-1000UA.job
- c:\users\Robin\AppData\Local\Facebook\Update\FacebookUpdate.exe [2014-01-19 19:20]
.
2014-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-05 13:50]
.
2014-02-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-12-05 13:50]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-02-03 18:02	287280	----a-w-	d:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Nvtmru"="c:\program files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe" [BU]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2013-03-29 13513288]
"ShadowPlay"="c:\windows\system32\nvspcap64.dll" [2014-01-21 1179576]
"NvBackend"="c:\program files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe" [2014-01-21 2234144]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2013-12-10 472984]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP32A90F07-5575-4C79-96E3-CFDB19C3D552&SSPV=
uDefault_Search_URL = hxxp://search.certified-toolbar.com?si=66807&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&st=chrome&q=
mDefault_Search_URL = hxxp://search.certified-toolbar.com?si=66807&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&st=chrome&q=
mStart Page = about:newtab
mLocal Page = c:\windows\SysWOW64\blank.htm
mSearch Page = hxxp://search.certified-toolbar.com?si=66807&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&st=chrome&q=
mSearch Bar = hxxp://search.certified-toolbar.com?si=66807&tid=6724&ver=5.7&ts=1392497969847&tguid=66817-8086-1392497969847-8DC38F95248515358FD0C9B6699636A2&st=chrome&q=
uInternet Settings,ProxyOverride = *.local
IE: An OneNote s&enden - d:\progra~2\MICROS~2\Office14\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - d:\progra~2\MICROS~2\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://search.conduit.com/?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP32A90F07-5575-4C79-96E3-CFDB19C3D552&SSPV=
FF - prefs.js: network.proxy.type - 2
FF - ExtSQL: 2014-02-15 22:59; {70ba6a57-dc09-4a3e-bbe1-dfb10af77244}; c:\users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\extensions\{70ba6a57-dc09-4a3e-bbe1-dfb10af77244}
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-SearchProtect - c:\progra~2\SearchProtect\Main\bin\uninstall.exe
AddRemove-{8D914DD2-F3CE-44E4-9498-E7EED093281C}_is1 - c:\program files (x86)\IndustrieGigant 2\unins000.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3062181239-1702867323-3627005284-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{14264a21-01fa-455f-a9c4-7c8b3d82b6f6}]
@Denied: (A 2) (Administrators)
@Denied: (A 2) (S-1-5-21-3062181239-1702867323-3627005284-1000)
"Flags"=dword:00000400
.
[HKEY_USERS\S-1-5-21-3062181239-1702867323-3627005284-1000\Software\SecuROM\License information*]
"datasecu"=hex:96,02,09,d0,90,fb,34,de,9d,dd,4d,cc,78,d8,15,aa,bb,da,c2,b2,92,
   26,4f,a5,ee,85,c0,81,68,9d,00,2c,5b,eb,3a,cc,13,1c,35,39,c0,d4,39,ec,33,11,\
"rkeysecu"=hex:29,23,be,84,e1,6c,d6,ae,52,90,49,f1,f1,bb,e9,eb
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_44_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_44_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_44_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_44_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_44.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_44.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_44.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_44.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2014-02-20  16:10:19
ComboFix-quarantined-files.txt  2014-02-20 15:10
ComboFix2.txt  2014-02-20 15:03
.
Vor Suchlauf: 8.345.473.024 Bytes frei
Nach Suchlauf: 8.282.427.392 Bytes frei
.
- - End Of File - - BE2E0874B2C0AC96ECAC8FD1B232322A
A36C5E4F47E84449FF07ED3517B43A31
         


Alt 21.02.2014, 11:13   #6
schrauber
/// the machine
/// TB-Ausbilder
 

browser.newtab.url ändert sich selbstständig auf "search.conduit.com" - Standard

browser.newtab.url ändert sich selbstständig auf "search.conduit.com"



Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
--> browser.newtab.url ändert sich selbstständig auf "search.conduit.com"

Alt 21.02.2014, 14:07   #7
Robin0308
 
browser.newtab.url ändert sich selbstständig auf "search.conduit.com" - Standard

browser.newtab.url ändert sich selbstständig auf "search.conduit.com"



Hey, da die Logs zulang geworden wären, musste ich sie als Archiv anfügen.

Alt 22.02.2014, 13:28   #8
schrauber
/// the machine
/// TB-Ausbilder
 

browser.newtab.url ändert sich selbstständig auf "search.conduit.com" - Standard

browser.newtab.url ändert sich selbstständig auf "search.conduit.com"



Hi,

Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen.


So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke auf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.





ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 22.02.2014, 18:46   #9
Robin0308
 
browser.newtab.url ändert sich selbstständig auf "search.conduit.com" - Standard

browser.newtab.url ändert sich selbstständig auf "search.conduit.com"



Alles klar, hier mal wieder ein paar Logs.

ESET:
Code:
ATTFilter
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=6a9cb6dbe43471428acf0a1afa7b1960
# engine=17180
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-02-22 03:30:00
# local_time=2014-02-22 04:30:00 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776573 100 94 16690806 144712850 0 0
# scanned=430207
# found=8
# cleaned=0
# scan_time=10173
sh=A065922E48E274F827BC8A04091A44632D498373 ft=1 fh=f3684398a5f5cf1b vn="Win64/Conedex.I trojan" ac=I fn="C:\Qoobox\Quarantine\C\Program Files (x86)\Google\Desktop\Install\{6294d68b-ece8-cdc3-21a7-ee57dc57ec05}\9519~1\A535~1\E628~1\{6294d68b-ece8-cdc3-21a7-ee57dc57ec05}\U\00000008.@.vir"
sh=A065922E48E274F827BC8A04091A44632D498373 ft=1 fh=f3684398a5f5cf1b vn="Win64/Conedex.I trojan" ac=I fn="C:\Qoobox\Quarantine\C\Users\Robin\AppData\Local\Google\Desktop\Install\{6294d68b-ece8-cdc3-21a7-ee57dc57ec05}\2E2F~1\28F0~1\E628~1\{6294d68b-ece8-cdc3-21a7-ee57dc57ec05}\U\00000008.@.vir"
sh=100C1C6DA6C6646025B17197B437512BE4D78FDC ft=1 fh=20804abc5174beae vn="a variant of Win32/Packed.VMProtect.ABD trojan" ac=I fn="D:\2-click run\Euro Truck Simulator 2 v1.7.1 (DLC Going East)\bin\win_x86\steam_api.dll"
sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="D:\Desktop\Seltene verwendete Datein\Sidler 7\rzr-set7.iso"
sh=021C8E26EB086088409ED1A0EA62075D3376A087 ft=0 fh=0000000000000000 vn="a variant of Win32/Packed.VMProtect.ABD trojan" ac=I fn="D:\downloads\3DMGAME-Euro.Truck.Simulator.2.Crack.Only-3DM.rar"
sh=14DA30021357111CB12267EFD6436C9791EB56F6 ft=1 fh=eb8748adfd5b0218 vn="Win32/AdWare.1ClickDownload.AQ application" ac=I fn="D:\downloads\4videosoft_mkv_video_converter_5_0_8___crack_[timetravel][h33t]_rar.exe"
sh=273A2A936AEC8B68DE2329EF69996F616B0D757E ft=1 fh=6e75ff11b16007d4 vn="NSIS/StartPage.CC trojan" ac=I fn="D:\downloads\vlc-2.1.3-win64.exe"
sh=E0994EAA49BEEF8898826541740DEEA33025FC55 ft=1 fh=de1440eb80b6f51a vn="a variant of Win32/Packed.VMProtect.AAA trojan" ac=I fn="D:\Program Files (x86)\Ubisoft\Die Siedler 7\Data\Base\_Dbg\Bin\Release\1911.dll"
         
SecurityCheck:
Code:
ATTFilter
 Results of screen317's Security Check version 0.99.79  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
``````````````Antivirus/Firewall Check:`````````````` 
avast! Antivirus   
 Antivirus up to date!  (On Access scanning disabled!) 
`````````Anti-malware/Other Utilities Check:````````` 
 Malwarebytes Anti-Malware Version 1.75.0.1300  
  Adobe Flash Player 12.0.0.70 Flash Player out of Date!  
 Adobe Reader XI  
 Mozilla Firefox (25.0) 
````````Process Check: objlist.exe by Laurent````````  
 AVAST Software Avast AvastSvc.exe  
 AVAST Software Avast AvastUI.exe  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log``````````````````````
         
FRST:

FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-02-2014 01
Ran by Robin (administrator) on ROBIN-PC on 22-02-2014 18:43:11
Running from C:\Users\Robin\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal



==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(AVAST Software) D:\Program Files\AVAST Software\Avast\AvastSvc.exe
() C:\Program Files (x86)\Zapp\WConnectorProductivity.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(TeamViewer GmbH) D:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(LogMeIn Inc.) D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(LogMeIn, Inc.) D:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(LogMeIn Inc.) D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(LogMeIn, Inc.) D:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(ICQ) C:\Users\Robin\AppData\Roaming\ICQM\icq.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIHAE.EXE
(Skype Technologies S.A.) D:\Program Files (x86)\Skype\Phone\Skype.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_IATIHAE.EXE
(Apple Inc.) D:\Program Files (x86)\iTunes\iTunesHelper.exe
() D:\Program Files\Hear\Hear.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(AVAST Software) D:\Program Files\AVAST Software\Avast\AvastUI.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncV1\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
(Valve Corporation) D:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(File Type Advisor) C:\Program Files (x86)\File Type Advisor\fileadvisor.exe
(Mozilla Corporation) D:\Program Files\Waterfox\waterfox.exe
(Mozilla Corporation) D:\Program Files\Waterfox\plugin-container.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Nvtmru] - "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13513288 2013-03-29] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] - C:\Windows\system32\nvspcap64.dll [1179576 2014-01-21] (NVIDIA Corporation)
HKLM\...\Run: [NvBackend] - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-01-21] (NVIDIA Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-12-10] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BCSSync] - D:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] - D:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] - D:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2239376 2014-02-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] - D:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-02-03] (AVAST Software)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3813712 2014-02-04] (LogMeIn Inc.)
HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [DAEMON Tools Lite] - D:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672640 2013-03-14] (Disc Soft Ltd)
HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [icq] - C:\Users\Robin\AppData\Roaming\ICQM\icq.exe [28698984 2013-08-06] (ICQ)
HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [Steam] - D:\Program Files (x86)\Steam\steam.exe [1822400 2014-02-20] (Valve Corporation)
HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [Skype] - D:\Program Files (x86)\Skype\Phone\Skype.exe [20584608 2013-11-14] (Skype Technologies S.A.)
HKU\S-1-5-21-3062181239-1702867323-3627005284-1000\...\Run: [EPLTarget\P0000000000000001] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xA1AB3F2ADF98CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {D9EE0C5C-6202-4940-AAAA-A7765605E923} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKLM - {D9EE0C5C-6202-4940-AAAA-A7765605E923} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKCU - {D9EE0C5C-6202-4940-AAAA-A7765605E923} URL = hxxp://www.sm.de/?q={searchTerms}
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - D:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Java\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Java\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Zapp - {14264a21-01fa-455f-a9c4-7c8b3d82b6f6} - C:\Program Files (x86)\Zapp\IE\Zapp.dll (Simply Tech LTD.)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - D:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - D:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - D:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM-x32 - Zapp - {14264a21-01fa-455f-a9c4-7c8b3d82b6f6} - C:\Program Files (x86)\Zapp\IE\Zapp.dll (Simply Tech LTD.)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 01 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 01 %SystemRoot%\System32\mswsock.dll [326144] (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870
FF NewTab: google.de
FF SelectedSearchEngine: Google
FF Homepage: google.de
FF NetworkProxy: "autoconfig_url", "data:text/javascript,function%20FindProxyForURL(url%2C%20host)%20%7Bif%20(shExpMatch(url%2C%20'http%3A%2F%2Fwww.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fext.last.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fsongza.com*')%20%7C%7C%20host%20%3D%3D%20's.hulu.com'%20%7C%7C%20url.indexOf('vevo.com')%20!%3D%20-1%20%7C%7C%20url.indexOf('play.google.com')%20!%3D%20-1%20%7C%7C%20(url.indexOf('youtube.com%2Fvideoplayback')%20!%3D%20-1%20%26%26%20url.indexOf('%26gcr%3Dus')%20!%3D%20-1%20%26%26%20url.indexOf('%26ptchn')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fplay.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.spotify.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.crunchyroll.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.funimation.com*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fsecure.funimation.com*')%20%7C%7C%20(url.indexOf('proxmate%3Dactive')%20!%3D%20-1%20%26%26%20url.indexOf('amazonaws.com')%20%3D%3D%20-1)%20%7C%7C%20(url.indexOf('proxmate%3Dus')%20!%3D%20-1)%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fwww.daisuki.net*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Faccount.beatsmusic.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.beatsmusic.com*')%20%7C%7C%20url.indexOf('discoverymedia.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fdsc.discovery.com%2F*')%20%7C%7C%20url.indexOf('southparkstudios.com')%20!%3D%20-1%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fgrooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fretro.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fhtml5.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Flisten.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.grooveshark.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpreview.grooveshark.com*')%20%7C%7C%20host%20%3D%3D%20'www.pandora.com'%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'https%3A%2F%2Fpiki.fm*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.mtv.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fmedia.mtvnservices.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.iheart.com*')%20%7C%7C%20shExpMatch(url%2C%20'http%3A%2F%2Fwww.rdio.com*'))%20%7B%20return%20'PROXY%20nq-us11.personalitycores.com%3A8000%3B%20PROXY%20nq-us07.personalitycores.com%3A8000%3B%20PROXY%20nq-us12.personalitycores.com%3A8000%3B%20PROXY%20nq-us06.personalitycores.com%3A8000%3B%20PROXY%20nq-us05.personalitycores.com%3A8000%3B%20PROXY%20nq-us10.personalitycores.com%3A8000%3B%20PROXY%20nq-us04.personalitycores.com%3A8000%3B%20PROXY%20nq-us08.personalitycores.com%3A8000%3B%20PROXY%20nq-us09.personalitycores.com%3A8000'%3B%7D%20%20else%20%7B%20return%20'DIRECT'%3B%20%7D%7D"
FF NetworkProxy: "type", 2
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll ()
FF Plugin: @java.com/DTPlugin,version=10.51.2 - D:\Java\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.51.2 - D:\Java\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.3 - D:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - D:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - D:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Robin\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Robin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF SearchPlugin: C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\searchplugins\search_engine.xml
FF Extension: Zapp - C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\Extensions\{70ba6a57-dc09-4a3e-bbe1-dfb10af77244} [2014-02-15]
FF Extension: ProxMate - Proxy on steroids! - C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\Extensions\jid1-QpHD8URtZWJC2A@jetpack.xpi [2013-12-19]
FF Extension: Deutsch (DE) Language Pack - C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\Extensions\langpack-de@firefox.mozilla.org.xpi [2014-02-05]
FF Extension: Adblock Plus - C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\6stx20st.default-1387489683870\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-19]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - D:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - D:\Program Files\AVAST Software\Avast\WebRep\FF [2013-08-27]
FF StartMenuInternet: FIREFOX.EXE - D:\Program Files\Mozilla Firefox\firefox.exe

==================== Services (Whitelisted) =================

R2 avast! Antivirus; D:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-02-03] (AVAST Software)
R2 Hamachi2Svc; D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2222416 2014-02-04] (LogMeIn Inc.)
S3 Microsoft SharePoint Workspace Audit Service; D:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [30969208 2010-03-25] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-01-21] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [16939296 2014-01-21] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2013-10-09] ()
S2 SkypeUpdate; D:\Program Files (x86)\Skype\Updater\Updater.exe [172192 2013-10-23] (Skype Technologies)
R2 TeamViewer8; D:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [4308320 2013-08-07] (TeamViewer GmbH)

==================== Drivers (Whitelisted) ====================

R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-02-03] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-11-23] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-23] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-02-03] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-02-03] (AVAST Software)
S3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-02-03] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2014-01-16] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-08-05] (DT Soft Ltd)
S3 GPCIDrv; C:\Program Files (x86)\GIGABYTE\GIGABYTE OC_GURU II\GPCIDrv64.sys [14376 2010-02-04] ()
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-27] (NVIDIA Corporation)
R3 REN2CAP_DRIVER; C:\Windows\System32\drivers\ren2cap.sys [46728 2011-11-07] ()
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-02-22 18:40 - 2014-02-22 18:40 - 00987425 _____ () C:\Users\Robin\Desktop\SecurityCheck.exe
2014-02-22 13:38 - 2014-02-22 13:38 - 02347384 _____ (ESET) C:\Users\Robin\Desktop\esetsmartinstaller_enu.exe
2014-02-21 14:06 - 2014-02-21 14:06 - 00026545 _____ () C:\Users\Robin\Desktop\Logfile.zip
2014-02-21 13:56 - 2014-02-22 18:43 - 00000000 ____D () C:\Users\Robin\Desktop\FRST-OlderVersion
2014-02-21 13:55 - 2014-02-21 13:55 - 00000990 _____ () C:\Users\Robin\Desktop\JRT.txt
2014-02-21 13:49 - 2014-02-21 13:49 - 01037734 _____ (Thisisu) C:\Users\Robin\Desktop\JRT.exe
2014-02-21 13:45 - 2014-02-21 13:45 - 00009292 _____ () C:\Users\Robin\Desktop\AdwCleaner[S1].txt
2014-02-21 13:43 - 2014-02-21 13:43 - 01241834 _____ () C:\Users\Robin\Desktop\adwcleaner.exe
2014-02-21 13:33 - 2014-02-21 13:33 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-02-21 13:33 - 2014-02-21 13:33 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Malwarebytes
2014-02-21 13:33 - 2014-02-21 13:33 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-21 13:33 - 2014-02-21 13:33 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-02-21 13:33 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-02-20 16:10 - 2014-02-20 16:10 - 00023466 _____ () C:\ComboFix.txt
2014-02-20 15:52 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-02-20 15:52 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-02-20 15:52 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-02-20 15:52 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-02-20 15:52 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-02-20 15:52 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-02-20 15:52 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-02-20 15:52 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-02-20 15:51 - 2014-02-20 16:10 - 00000000 ____D () C:\Qoobox
2014-02-20 15:51 - 2014-02-20 16:02 - 00000000 ____D () C:\Windows\erdnt
2014-02-20 15:51 - 2014-02-20 15:51 - 05183254 ____R (Swearware) C:\Users\Robin\Desktop\ComboFix.exe
2014-02-19 17:42 - 2014-02-19 17:42 - 00035833 _____ () C:\Users\Robin\Desktop\Addition.txt
2014-02-19 17:41 - 2014-02-22 18:43 - 02154496 _____ (Farbar) C:\Users\Robin\Desktop\FRST64.exe
2014-02-19 17:41 - 2014-02-22 18:43 - 00019788 _____ () C:\Users\Robin\Desktop\FRST.txt
2014-02-19 17:41 - 2014-02-22 18:43 - 00000000 ____D () C:\FRST
2014-02-18 22:40 - 2014-02-18 22:40 - 00000000 ____D () C:\Users\Robin\AppData\Local\My Games
2014-02-18 22:28 - 2014-02-18 22:28 - 00000221 _____ () C:\Users\Robin\Desktop\Sid Meier's Civilization V - Demo.url
2014-02-18 21:23 - 2014-02-18 21:23 - 00006477 _____ () C:\Users\Robin\AppData\Local\recently-used.xbel
2014-02-16 17:01 - 2014-02-16 17:01 - 00000000 ____D () C:\Users\Robin\.MCTranscodingSDK
2014-02-16 17:00 - 2014-02-16 17:05 - 00000000 ____D () C:\Users\Public\Documents\Lightworks
2014-02-16 17:00 - 2014-02-16 17:00 - 00000000 ____D () C:\ProgramData\Geevs
2014-02-15 22:19 - 2014-02-15 22:29 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-02-15 21:59 - 2014-02-21 13:45 - 00000000 ____D () C:\Windows\System32\Tasks\Browser Updater
2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Windows\System32\Tasks\SystemSockets
2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Program Files\Zapp
2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Program Files (x86)\Zapp
2014-02-15 21:59 - 2014-02-04 06:36 - 00033864 _____ () C:\Windows\Launcher.exe
2014-02-15 21:18 - 2014-02-15 21:18 - 00015130 _____ () C:\Users\Robin\Documents\Mein Film.wlmp
2014-02-15 20:34 - 2014-02-15 20:52 - 591803806 _____ () C:\Users\Robin\Desktop\template.avi
2014-02-15 20:34 - 2014-02-15 20:52 - 591803806 _____ () C:\Users\Robin\Desktop\A_template.avi
2014-02-15 19:16 - 2014-02-16 22:37 - 00000000 ____D () C:\Users\Robin\Desktop\INTRO TEMPLATE BY RenttuArts
2014-02-12 22:45 - 2014-02-12 22:45 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-02-12 22:45 - 2014-02-12 22:45 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-02-12 22:45 - 2014-02-12 22:45 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-02-12 22:45 - 2014-02-12 22:45 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-02-10 19:33 - 2014-02-10 19:33 - 00000934 _____ () C:\Users\Robin\Desktop\Landwirtschafts Simulator 2013 .lnk
2014-02-10 17:26 - 2014-02-10 17:26 - 00000000 ____D () C:\Users\Robin\AppData\Local\EdgeOfReality
2014-02-10 16:08 - 2014-02-10 16:08 - 00000222 _____ () C:\Users\Robin\Desktop\Loadout.url
2014-02-09 22:33 - 2014-02-14 23:32 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\vlc
2014-02-09 22:33 - 2014-02-09 22:33 - 00000757 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-02-09 17:25 - 2014-02-09 17:25 - 00000836 _____ () C:\Users\Public\Desktop\Prime Time.lnk
2014-02-05 18:57 - 2014-02-22 11:14 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\.minecraft
2014-02-04 16:51 - 2014-02-04 16:51 - 00003012 _____ () C:\Windows\System32\Tasks\{29949044-F7D7-4E68-B9CE-644E4CFDA5BB}
2014-02-03 20:36 - 2014-02-03 20:36 - 00001648 _____ () C:\Users\Robin\Desktop\Euro Truck Simulator 2.lnk
2014-02-03 18:45 - 2014-02-03 18:45 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1-click run
2014-02-03 18:44 - 2014-02-03 18:44 - 00000000 ____D () C:\2-click run
2014-01-30 16:10 - 2014-01-30 16:10 - 00012834 _____ () C:\Users\Robin\Desktop\Anno2070.lnk
2014-01-30 16:02 - 2014-01-30 16:02 - 00001468 _____ () C:\Users\Robin\Desktop\Flight Simulator X.lnk
2014-01-29 20:02 - 2014-01-29 20:02 - 00038960 _____ () C:\Windows\SysWOW64\RGBAcodec.dll
2014-01-28 21:01 - 2014-02-16 17:46 - 00000000 ___RD () C:\Users\Robin\Desktop\Aufnehmzeug
2014-01-26 21:29 - 2013-12-19 21:33 - 30372640 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 25257248 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 22960416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 18222008 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 12645664 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-01-26 21:29 - 2013-12-19 21:33 - 11605752 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 11554264 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 09700224 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 09657464 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 03132704 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 03125024 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 02947872 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 02747680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 01884448 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433221.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433221.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 01242400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00882464 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00879392 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00852768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00847648 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00479520 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00405280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00357152 _____ () C:\Windows\system32\NvIFROpenGL.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00317472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00314656 _____ () C:\Windows\SysWOW64\NvIFROpenGL.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00266984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00168616 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2014-01-26 21:29 - 2013-12-19 21:33 - 00141336 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2014-01-26 21:29 - 2013-11-28 14:38 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2014-01-26 21:29 - 2013-11-28 14:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2014-01-26 21:29 - 2013-11-22 09:36 - 01515296 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2014-01-26 21:26 - 2013-12-27 19:42 - 00039200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2014-01-26 21:26 - 2013-12-27 19:42 - 00033056 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2014-01-26 01:00 - 2014-02-22 11:04 - 00007206 _____ () C:\Windows\setupact.log
2014-01-26 01:00 - 2014-01-26 01:00 - 00000000 _____ () C:\Windows\setuperr.log
2014-01-25 17:52 - 2014-01-25 17:52 - 00000000 ____D () C:\Users\Robin\.cache
2014-01-25 15:28 - 2014-01-26 17:48 - 03276780 _____ () C:\Users\Robin\Desktop\Schülerpraktikumsbericht.pptx

==================== One Month Modified Files and Folders =======

2014-02-22 18:43 - 2014-02-21 13:56 - 00000000 ____D () C:\Users\Robin\Desktop\FRST-OlderVersion
2014-02-22 18:43 - 2014-02-19 17:41 - 02154496 _____ (Farbar) C:\Users\Robin\Desktop\FRST64.exe
2014-02-22 18:43 - 2014-02-19 17:41 - 00019788 _____ () C:\Users\Robin\Desktop\FRST.txt
2014-02-22 18:43 - 2014-02-19 17:41 - 00000000 ____D () C:\FRST
2014-02-22 18:41 - 2013-08-05 17:20 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Skype
2014-02-22 18:40 - 2014-02-22 18:40 - 00987425 _____ () C:\Users\Robin\Desktop\SecurityCheck.exe
2014-02-22 18:06 - 2013-12-05 14:50 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-22 17:51 - 2013-08-04 23:29 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-22 17:25 - 2014-01-19 20:20 - 00000928 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3062181239-1702867323-3627005284-1000UA.job
2014-02-22 15:58 - 2013-08-04 22:39 - 01405874 _____ () C:\Windows\WindowsUpdate.log
2014-02-22 13:41 - 2009-07-14 05:45 - 00015760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-22 13:41 - 2009-07-14 05:45 - 00015760 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-22 13:38 - 2014-02-22 13:38 - 02347384 _____ (ESET) C:\Users\Robin\Desktop\esetsmartinstaller_enu.exe
2014-02-22 13:38 - 2009-07-14 18:58 - 00699394 _____ () C:\Windows\system32\perfh007.dat
2014-02-22 13:38 - 2009-07-14 18:58 - 00149534 _____ () C:\Windows\system32\perfc007.dat
2014-02-22 13:38 - 2009-07-14 06:13 - 01620346 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-22 12:43 - 2013-08-24 11:43 - 00000000 ____D () C:\Program Files (x86)\File Type Advisor
2014-02-22 11:14 - 2014-02-05 18:57 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\.minecraft
2014-02-22 11:04 - 2014-01-26 01:00 - 00007206 _____ () C:\Windows\setupact.log
2014-02-22 11:04 - 2014-01-06 16:45 - 00000000 ____D () C:\Users\Robin\AppData\Local\LogMeIn Hamachi
2014-02-22 11:04 - 2013-12-05 14:50 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-22 11:04 - 2013-08-17 09:34 - 00000000 ____D () C:\Users\Robin\AppData\Local\Adobe
2014-02-22 11:04 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-22 11:03 - 2013-08-04 22:49 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-02-21 20:25 - 2014-01-19 20:20 - 00000906 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3062181239-1702867323-3627005284-1000Core.job
2014-02-21 14:51 - 2013-08-04 23:29 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-02-21 14:51 - 2013-08-04 23:29 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-02-21 14:51 - 2013-08-04 23:29 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-02-21 14:06 - 2014-02-21 14:06 - 00026545 _____ () C:\Users\Robin\Desktop\Logfile.zip
2014-02-21 13:55 - 2014-02-21 13:55 - 00000990 _____ () C:\Users\Robin\Desktop\JRT.txt
2014-02-21 13:49 - 2014-02-21 13:49 - 01037734 _____ (Thisisu) C:\Users\Robin\Desktop\JRT.exe
2014-02-21 13:48 - 2013-12-19 22:16 - 00000000 ____D () C:\AdwCleaner
2014-02-21 13:47 - 2013-08-27 17:24 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-02-21 13:45 - 2014-02-21 13:45 - 00009292 _____ () C:\Users\Robin\Desktop\AdwCleaner[S1].txt
2014-02-21 13:45 - 2014-02-15 21:59 - 00000000 ____D () C:\Windows\System32\Tasks\Browser Updater
2014-02-21 13:43 - 2014-02-21 13:43 - 01241834 _____ () C:\Users\Robin\Desktop\adwcleaner.exe
2014-02-21 13:43 - 2013-11-08 18:53 - 00000000 ____D () C:\Users\Robin\AppData\Local\Apps\2.0
2014-02-21 13:41 - 2013-08-05 09:37 - 00423784 _____ () C:\Windows\PFRO.log
2014-02-21 13:33 - 2014-02-21 13:33 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-02-21 13:33 - 2014-02-21 13:33 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Malwarebytes
2014-02-21 13:33 - 2014-02-21 13:33 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-02-21 13:33 - 2014-02-21 13:33 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-02-20 16:10 - 2014-02-20 16:10 - 00023466 _____ () C:\ComboFix.txt
2014-02-20 16:10 - 2014-02-20 15:51 - 00000000 ____D () C:\Qoobox
2014-02-20 16:09 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2014-02-20 16:03 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2014-02-20 16:02 - 2014-02-20 15:51 - 00000000 ____D () C:\Windows\erdnt
2014-02-20 15:55 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-02-20 15:51 - 2014-02-20 15:51 - 05183254 ____R (Swearware) C:\Users\Robin\Desktop\ComboFix.exe
2014-02-19 17:42 - 2014-02-19 17:42 - 00035833 _____ () C:\Users\Robin\Desktop\Addition.txt
2014-02-19 12:07 - 2013-08-05 09:42 - 00124616 _____ () C:\Users\Robin\AppData\Local\GDIPFONTCACHEV1.DAT
2014-02-19 12:06 - 2009-07-14 05:45 - 05108968 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-02-18 22:40 - 2014-02-18 22:40 - 00000000 ____D () C:\Users\Robin\AppData\Local\My Games
2014-02-18 22:40 - 2013-10-21 15:35 - 00000000 ____D () C:\Users\Robin\Documents\My Games
2014-02-18 22:40 - 2013-08-05 23:41 - 00435159 _____ () C:\Windows\DirectX.log
2014-02-18 22:28 - 2014-02-18 22:28 - 00000221 _____ () C:\Users\Robin\Desktop\Sid Meier's Civilization V - Demo.url
2014-02-18 21:46 - 2013-08-07 20:08 - 00000000 ____D () C:\Users\Robin\Documents\Euro Truck Simulator 2
2014-02-18 21:23 - 2014-02-18 21:23 - 00006477 _____ () C:\Users\Robin\AppData\Local\recently-used.xbel
2014-02-18 21:23 - 2013-08-05 23:05 - 00000000 ____D () C:\Users\Robin\AppData\Local\gtk-2.0
2014-02-18 21:23 - 2013-08-05 23:03 - 00000000 ____D () C:\Users\Robin\.gimp-2.8
2014-02-16 22:37 - 2014-02-15 19:16 - 00000000 ____D () C:\Users\Robin\Desktop\INTRO TEMPLATE BY RenttuArts
2014-02-16 19:27 - 2013-08-05 18:32 - 00007602 _____ () C:\Users\Robin\AppData\Local\Resmon.ResmonCfg
2014-02-16 17:46 - 2014-01-28 21:01 - 00000000 ___RD () C:\Users\Robin\Desktop\Aufnehmzeug
2014-02-16 17:05 - 2014-02-16 17:00 - 00000000 ____D () C:\Users\Public\Documents\Lightworks
2014-02-16 17:01 - 2014-02-16 17:01 - 00000000 ____D () C:\Users\Robin\.MCTranscodingSDK
2014-02-16 17:01 - 2013-08-04 22:37 - 00000000 ____D () C:\Users\Robin
2014-02-16 17:00 - 2014-02-16 17:00 - 00000000 ____D () C:\ProgramData\Geevs
2014-02-15 22:45 - 2013-08-04 22:37 - 00000000 ___RD () C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-02-15 22:29 - 2014-02-15 22:19 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-02-15 22:28 - 2013-11-12 18:16 - 00000000 ____D () C:\Program Files\Adobe
2014-02-15 22:19 - 2013-08-17 09:34 - 00000000 ____D () C:\ProgramData\Adobe
2014-02-15 22:19 - 2013-08-04 23:29 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Adobe
2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Windows\System32\Tasks\SystemSockets
2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Program Files\Zapp
2014-02-15 21:59 - 2014-02-15 21:59 - 00000000 ____D () C:\Program Files (x86)\Zapp
2014-02-15 21:18 - 2014-02-15 21:18 - 00015130 _____ () C:\Users\Robin\Documents\Mein Film.wlmp
2014-02-15 20:52 - 2014-02-15 20:34 - 591803806 _____ () C:\Users\Robin\Desktop\template.avi
2014-02-15 20:52 - 2014-02-15 20:34 - 591803806 _____ () C:\Users\Robin\Desktop\A_template.avi
2014-02-15 15:29 - 2013-12-25 21:24 - 02346186 _____ () C:\Users\Robin\Desktop\TechnicLauncher.exe
2014-02-15 15:29 - 2013-10-26 18:16 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\.technic
2014-02-14 23:32 - 2014-02-09 22:33 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\vlc
2014-02-12 22:45 - 2014-02-12 22:45 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-02-12 22:45 - 2014-02-12 22:45 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-02-12 22:45 - 2014-02-12 22:45 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-02-12 22:45 - 2014-02-12 22:45 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2014-02-12 21:01 - 2013-12-05 14:50 - 00004104 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-02-12 21:01 - 2013-12-05 14:50 - 00003852 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-02-10 19:33 - 2014-02-10 19:33 - 00000934 _____ () C:\Users\Robin\Desktop\Landwirtschafts Simulator 2013 .lnk
2014-02-10 17:26 - 2014-02-10 17:26 - 00000000 ____D () C:\Users\Robin\AppData\Local\EdgeOfReality
2014-02-10 16:08 - 2014-02-10 16:08 - 00000222 _____ () C:\Users\Robin\Desktop\Loadout.url
2014-02-09 22:33 - 2014-02-09 22:33 - 00000757 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-02-09 17:25 - 2014-02-09 17:25 - 00000836 _____ () C:\Users\Public\Desktop\Prime Time.lnk
2014-02-04 16:51 - 2014-02-04 16:51 - 00003012 _____ () C:\Windows\System32\Tasks\{29949044-F7D7-4E68-B9CE-644E4CFDA5BB}
2014-02-04 06:36 - 2014-02-15 21:59 - 00033864 _____ () C:\Windows\Launcher.exe
2014-02-03 22:18 - 2013-08-05 23:55 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\uTorrent
2014-02-03 20:36 - 2014-02-03 20:36 - 00001648 _____ () C:\Users\Robin\Desktop\Euro Truck Simulator 2.lnk
2014-02-03 19:03 - 2013-08-27 17:24 - 00001040 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-02-03 19:02 - 2014-01-16 21:19 - 00080184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-02-03 19:02 - 2013-08-27 17:24 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-02-03 19:02 - 2013-08-27 17:24 - 00421704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-02-03 19:02 - 2013-08-27 17:24 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-02-03 19:02 - 2013-08-27 17:24 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-02-03 19:02 - 2013-08-27 17:24 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-02-03 18:45 - 2014-02-03 18:45 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1-click run
2014-02-03 18:44 - 2014-02-03 18:44 - 00000000 ____D () C:\2-click run
2014-01-30 16:38 - 2013-11-24 15:58 - 00000781 _____ () C:\Users\Robin\Desktop\TransportGigant.lnk
2014-01-30 16:10 - 2014-01-30 16:10 - 00012834 _____ () C:\Users\Robin\Desktop\Anno2070.lnk
2014-01-30 16:03 - 2013-08-30 22:11 - 00000000 ____D () C:\Users\Robin\AppData\Roaming\Virtuali
2014-01-30 16:03 - 2013-08-30 22:11 - 00000000 ____D () C:\ProgramData\Virtuali
2014-01-30 16:02 - 2014-01-30 16:02 - 00001468 _____ () C:\Users\Robin\Desktop\Flight Simulator X.lnk
2014-01-29 20:02 - 2014-01-29 20:02 - 00038960 _____ () C:\Windows\SysWOW64\RGBAcodec.dll
2014-01-27 19:49 - 2013-11-21 22:33 - 00000000 ____D () C:\Users\Robin\AppData\Local\Microsoft Games
2014-01-26 21:30 - 2013-08-04 22:49 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-01-26 17:48 - 2014-01-25 15:28 - 03276780 _____ () C:\Users\Robin\Desktop\Schülerpraktikumsbericht.pptx
2014-01-26 01:00 - 2014-01-26 01:00 - 00000000 _____ () C:\Windows\setuperr.log
2014-01-25 17:52 - 2014-01-25 17:52 - 00000000 ____D () C:\Users\Robin\.cache

Some content of TEMP:
====================
C:\Users\Robin\AppData\Local\Temp\Quarantine.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-02-19 12:50

==================== End Of Log ============================
         
--- --- ---

--- --- ---

Alt 23.02.2014, 16:35   #10
schrauber
/// the machine
/// TB-Ausbilder
 

browser.newtab.url ändert sich selbstständig auf "search.conduit.com" - Standard

browser.newtab.url ändert sich selbstständig auf "search.conduit.com"



Funde von ESET bitte manuell löschen.


Fertig

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.



Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun

Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 23.02.2014, 22:29   #11
Robin0308
 
browser.newtab.url ändert sich selbstständig auf "search.conduit.com" - Standard

browser.newtab.url ändert sich selbstständig auf "search.conduit.com"



Hey, vielen Dank für deine Hilfe, es hat soweit geklappt und ich habe die Programme entfernt.
Jedoch habe ich jetzt scheinbar ein anderes Problem, es geht darum das mein Internet, seit dem entfernen, langsamer geworden ist, am meisten fällt es mir bei YT Videos auf, sie laden nicht mehr richtig oder garnicht mehr.
Kommt sowas mal vor?
Neugestartet habe ich schon 2 mal.

Grüße Robin

Alt 24.02.2014, 18:40   #12
schrauber
/// the machine
/// TB-Ausbilder
 

browser.newtab.url ändert sich selbstständig auf "search.conduit.com" - Standard

browser.newtab.url ändert sich selbstständig auf "search.conduit.com"



In welchem Browser?
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 25.02.2014, 14:26   #13
Robin0308
 
browser.newtab.url ändert sich selbstständig auf "search.conduit.com" - Standard

browser.newtab.url ändert sich selbstständig auf "search.conduit.com"



Firefox bzw. Waterfox

Alt 26.02.2014, 12:21   #14
schrauber
/// the machine
/// TB-Ausbilder
 

browser.newtab.url ändert sich selbstständig auf "search.conduit.com" - Standard

browser.newtab.url ändert sich selbstständig auf "search.conduit.com"



Revo Uninstaller - Download - Filepony
damit Firefox deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren.

Dann:
https://support.mozilla.org/de/kb/fi...einfach-loesen
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu browser.newtab.url ändert sich selbstständig auf "search.conduit.com"
.com, avast, avast!, frage, fragen, guten, immer wieder, mobogenie, mobogenie entfernen, nichts, nsis/startpage.cc, problem, schonmal, selbstständig, win32/adware.1clickdownload.aq, win32/packed.vmprotect.aaa, win32/packed.vmprotect.abd, win64/conedex.i, woche, zusammen



Ähnliche Themen: browser.newtab.url ändert sich selbstständig auf "search.conduit.com"


  1. Virusname: "searchinterneat-a.akamaihd". Öffnet selbstständig Browser-Fenster
    Plagegeister aller Art und deren Bekämpfung - 15.11.2015 (22)
  2. Fehlerhinweis "Ungültiges Bild" unter WINDOWS 7: "C:\PROGRA~2\SEARCH~2\SEARCH~1\bin\VC32LO~1.DLL" +
    Log-Analyse und Auswertung - 19.04.2015 (9)
  3. Mauszeiger bewegt sich selbstständig, Sound "knistert"
    Log-Analyse und Auswertung - 10.01.2015 (16)
  4. Windows 8 / "Feun2Save": Nur noch Werbelinks usw. im Browser; Browser öffnet sich von alleine
    Log-Analyse und Auswertung - 06.10.2014 (18)
  5. Startseite "http://search.conduit.com"
    Plagegeister aller Art und deren Bekämpfung - 15.04.2014 (11)
  6. das Problem mit dem "search.conduit.com"
    Plagegeister aller Art und deren Bekämpfung - 21.02.2014 (11)
  7. Windows 8: Laptop nach "Conduit Search & Trovigo.com Startseite" sauber?
    Plagegeister aller Art und deren Bekämpfung - 17.02.2014 (7)
  8. OTL Analyse "Problem: search conduit" nach codec installation
    Log-Analyse und Auswertung - 03.02.2014 (2)
  9. selbstständig öffnende Browser-Werbefenster und "DataMngr" konnte nicht entfernt werden
    Log-Analyse und Auswertung - 22.01.2014 (9)
  10. "monstermarketplace.com" Infektion und ihre Folgen; "Anti-Virus-Blocker"," unsichtbare Toolbars" + "Browser-Hijacker" von selbst installiert
    Log-Analyse und Auswertung - 16.11.2013 (21)
  11. Fehlermeldung beim Start "Users\[name]\AppData\Local\Conduit ..." gehabt. Conduit gelöscht aber weiterhin Probleme
    Log-Analyse und Auswertung - 15.11.2013 (9)
  12. Nach Installation plötzlich immer Seite "http://start.iminent.com/StartWeb/1031/newtab/Newtab.aspx" im neuen Tab
    Plagegeister aller Art und deren Bekämpfung - 11.10.2013 (20)
  13. Gleich Problem wie User (trauma)? Es öffnen sich selbstständig "Sponsorship" Tabs. Wie kann ich es entfernen.
    Log-Analyse und Auswertung - 12.09.2013 (3)
  14. "Windows wird gestartet" freeze, Festplatte macht sich selbstständig, Was ist denn jetzt los?
    Alles rund um Windows - 27.08.2013 (3)
  15. Windows 7: "http://search.conduit.com/" in neuen Firefox-Tabs
    Log-Analyse und Auswertung - 06.08.2013 (11)
  16. Habe mir "search.conduit.com" im IE eingefangen
    Log-Analyse und Auswertung - 18.03.2013 (7)
  17. "Search Settings Notification" + Web-Browser starten langsam
    Log-Analyse und Auswertung - 07.12.2011 (28)

Zum Thema browser.newtab.url ändert sich selbstständig auf "search.conduit.com" - Guten Tag zusammen, ich habe seit nun schon ca. 1 Woche das Problem, das sich die browser.newtab.url immer wieder von "google.de" auf "search.conduit.com" ändert. Das ist nicht nur nervig sondern, - browser.newtab.url ändert sich selbstständig auf "search.conduit.com"...
Archiv
Du betrachtest: browser.newtab.url ändert sich selbstständig auf "search.conduit.com" auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.